Facturare WooCommerce Security & Risk Analysis

wordpress.org/plugins/facturare-persoana-fizica-sau-juridica

Adaugă câmpurile necesare facturării persoanelor fizice sau juridice conform legislației din Romania în vigoare.

3K active installs v1.2.6 PHP + WP 3.5+ Updated Feb 28, 2025
facturarepersoana-fizicapersoana-juridicawoocommerce
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Facturare WooCommerce Safe to Use in 2026?

Generally Safe

Score 92/100

Facturare WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The plugin "facturare-persoana-fizica-sau-juridica" v1.2.6 exhibits a generally good security posture with several positive indicators. The absence of dangerous functions, file operations, and external HTTP requests is commendable. Furthermore, all SQL queries utilize prepared statements, and a high percentage of output is properly escaped, mitigating common web vulnerabilities. The plugin also incorporates nonces and capability checks for its entry points.

However, a significant concern arises from the presence of one unprotected AJAX handler. This creates a direct attack vector that could be exploited if not properly secured through other means not evident in this analysis. While the taint analysis shows no issues, the lack of authentication on an AJAX endpoint represents a tangible risk, particularly if sensitive operations can be triggered through it. The vulnerability history is clean, which is a positive sign, but the single unprotected entry point remains a weakness that needs to be addressed.

In conclusion, the plugin demonstrates good development practices in many areas, particularly regarding data handling and escaping. The lack of known vulnerabilities in its history is a strength. Nevertheless, the unprotected AJAX handler is a critical oversight that significantly lowers its overall security score and warrants immediate attention to prevent potential exploits.

Key Concerns

  • Unprotected AJAX handler detected
  • AJAX entry point without explicit auth check
Vulnerabilities
None known

Facturare WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Facturare WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
33 escaped
Nonce Checks
2
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

85% escaped39 total outputs
Attack Surface
1 unprotected

Facturare WooCommerce Attack Surface

Entry Points2
Unprotected1

AJAX Handlers 2

authwp_ajax_woo_facturare_reviewadmin\class-facturare-review.php:36
authwp_ajax_woofacturareproincludes\class-facturare.php:102
WordPress Hooks 53
actioninitadmin\class-facturare-review.php:23
actionadmin_noticesadmin\class-facturare-review.php:35
actionadmin_enqueue_scriptsadmin\class-facturare-review.php:37
actionadmin_print_footer_scriptsadmin\class-facturare-review.php:38
actionplugins_loadedincludes\class-facturare.php:41
filterwoocommerce_get_settings_pagesincludes\class-facturare.php:52
filterwc_admin_page_tab_sectionsincludes\class-facturare.php:53
filterplugin_action_linksincludes\class-facturare.php:56
actionwoocommerce_checkout_update_order_metaincludes\class-facturare.php:59
actionwoocommerce_checkout_update_user_metaincludes\class-facturare.php:62
filterwoocommerce_order_formatted_billing_addressincludes\class-facturare.php:65
filterwoocommerce_my_account_my_address_formatted_addressincludes\class-facturare.php:66
filterwoocommerce_formatted_address_replacementsincludes\class-facturare.php:67
filterwoocommerce_localisation_address_formatsincludes\class-facturare.php:68
actionadmin_menuincludes\class-facturare.php:71
actionwoocommerce_page_wc-settingsincludes\class-facturare.php:77
actionwoocommerce_page_wc-settingsincludes\class-facturare.php:78
actionwoocommerce_page_wc-settingsincludes\class-facturare.php:79
actionwoocommerce_page_wc-settingsincludes\class-facturare.php:80
filterwoo_pdf_macrosincludes\class-facturare.php:83
filterwoocommerce_admin_billing_fieldsincludes\class-facturare.php:86
filterwoocommerce_order_get__billing_tip_facturareincludes\class-facturare.php:87
filterwoocommerce_order_get__billing_cnpincludes\class-facturare.php:88
filterwoocommerce_order_get__billing_cuiincludes\class-facturare.php:89
filterwoocommerce_order_get__billing_nume_bancaincludes\class-facturare.php:90
filterwoocommerce_order_get__billing_nr_reg_comincludes\class-facturare.php:91
filterwoocommerce_order_get__billing_ibanincludes\class-facturare.php:92
actionwoocommerce_process_shop_order_metaincludes\class-facturare.php:95
actionadmin_enqueue_scriptsincludes\class-facturare.php:98
actionadmin_noticesincludes\class-facturare.php:101
actionadmin_enqueue_scriptsincludes\class-facturare.php:103
actionadmin_print_footer_scriptsincludes\class-facturare.php:104
filterwoocommerce_ajax_get_customer_detailsincludes\class-facturare.php:107
actionadd_meta_boxesincludes\class-facturare.php:110
actionwp_headincludes\class-facturare.php:118
actionwp_footerincludes\class-facturare.php:119
filterwoocommerce_billing_fieldsincludes\class-facturare.php:122
filterwoocommerce_form_fieldincludes\class-facturare.php:123
filterwoocommerce_form_field_argsincludes\class-facturare.php:124
filterwoocommerce_checkout_fieldsincludes\class-facturare.php:125
actionwoocommerce_checkout_processincludes\class-facturare.php:128
filterwoocommerce_address_to_editincludes\class-facturare.php:131
filterwoocommerce_customer_save_addressincludes\class-facturare.php:133
filterget_post_metadataincludes\class-facturare.php:136
filterwoo_smartbill_dataincludes\class-facturare.php:139
filterwoocommerce_oblio_invoice_dataincludes\class-facturare.php:143
filteres_order_info_transformincludes\class-facturare.php:146
filterwoe_get_order_fieldsincludes\compatibilities.php:4
filterwoe_get_order_value_woofact_cuiincludes\compatibilities.php:40
filterwoe_get_order_value_woofact_cnpincludes\compatibilities.php:46
filterwoe_get_order_value_woofact_nrregcomincludes\compatibilities.php:52
filterwoe_get_order_value_woofact_bancaincludes\compatibilities.php:58
filterwoe_get_order_value_woofact_ibanincludes\compatibilities.php:64
Maintenance & Trust

Facturare WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedFeb 28, 2025
PHP min version
Downloads26K

Community Trust

Rating100/100
Number of ratings53
Active installs3K
Developer Profile

Facturare WooCommerce Developer Profile

George Ciobanu

2 plugins · 3K total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Facturare WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/facturare-persoana-fizica-sau-juridica/assets/css/facturare-checkout.css/wp-content/plugins/facturare-persoana-fizica-sau-juridica/assets/js/facturare-checkout.js

HTML / DOM Fingerprints

CSS Classes
facturare-checkout-formfacturare-pers-fiz-fieldsfacturare-pers-jur-fieldswoocommerce-facturare-settings
Data Attributes
data-facturare-tipdata-facturare-pers-fiz-cnp-vizibilitydata-facturare-pers-fiz-cnp-requireddata-facturare-pers-jur-company-vizibilitydata-facturare-pers-jur-company-requireddata-facturare-pers-jur-cui-vizibility+7 more
JS Globals
window.av_facturare_settings
FAQ

Frequently Asked Questions about Facturare WooCommerce