
Facturis Sync Security & Risk Analysis
wordpress.org/plugins/facturis-online-syncSynchronize data between your Woocommerce store and your Facturis Online account.
Is Facturis Sync Safe to Use in 2026?
Generally Safe
Score 85/100Facturis Sync has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'facturis-online-sync' plugin version 2.1.8 exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for SQL queries and shows no recorded vulnerability history. However, significant security concerns are present within its attack surface and code analysis.
A primary concern is the presence of 14 AJAX handlers, with a substantial 6 of them lacking authentication checks. This creates a considerable entry point for attackers to potentially exploit these unprotected handlers. Furthermore, the taint analysis revealed 2 flows with unsanitized paths, which, while not reaching critical or high severity in this specific analysis, still represent a risk if these paths are exposed to user-controlled input.
The plugin also shows weaknesses in output escaping, with only 19% of outputs being properly escaped. This increases the risk of cross-site scripting (XSS) vulnerabilities. The absence of capability checks on any AJAX handlers is another area of concern. While the plugin has no known CVEs, the identified code-level weaknesses, particularly the unprotected AJAX actions and insufficient output escaping, indicate areas where vulnerabilities could be introduced or exploited. The plugin's strengths lie in its SQL query handling and lack of historical vulnerabilities, but these are overshadowed by the identified risks in its exposed functionality and data handling.
Key Concerns
- Unprotected AJAX handlers
- Insufficient output escaping
- Flows with unsanitized paths
- No capability checks on AJAX
Facturis Sync Security Vulnerabilities
Facturis Sync Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Facturis Sync Attack Surface
AJAX Handlers 14
WordPress Hooks 16
Scheduled Events 1
Maintenance & Trust
Facturis Sync Maintenance & Trust
Maintenance Signals
Community Trust
Facturis Sync Alternatives
Facturare WooCommerce
facturare-persoana-fizica-sau-juridica
Adaugă câmpurile necesare facturării persoanelor fizice sau juridice conform legislației din Romania în vigoare.
Romanian billing fields
romanian-billing-fields
Adaugă automat câmpuri de facturare în limba română la WooCommerce Checkout
FACTO – Facturación Electrónica
facto-facturacioacuten-electroacutenica
Con este plugin Integra el módulo FACTO con tu sitio web y automatiza la emisión de documentos electrónicos cada vez que recibes una compra.
Contabilium Oficial para WooCommerce
contabilium-oficial-para-woo
Contabilium es un sistema de gestión online que te permite administrar todos tus ingresos y gastos de una forma sencilla y rápida en cualquier momento …
Comprobante de Pago Perú
comprobante-de-pago-peru
Payment Receipt for Peru where the option to choose bill or Invoice or others is added.
Facturis Sync Developer Profile
1 plugin · 10 total installs
How We Detect Facturis Sync
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/facturis-online-sync/View/css/main.css/wp-content/plugins/facturis-online-sync/View/css/form.css/wp-content/plugins/facturis-online-sync/View/vanillajs-datepicker/dist/css/datepicker.min.css/wp-content/plugins/facturis-online-sync/View/vanillajs-datepicker/dist/css/datepicker-bs4.min.css/wp-content/plugins/facturis-online-sync/View/vanillajs-datepicker/dist/js/datepicker-full.min.js/wp-content/plugins/facturis-online-sync/View/js/tab1.js/wp-content/plugins/facturis-online-sync/View/js/tab2.js/wp-content/plugins/facturis-online-sync/View/js/tab3.js+2 morefacturis-online-sync/View/css/main.css?ver=facturis-online-sync/View/css/form.css?ver=facturis-online-sync/View/vanillajs-datepicker/dist/css/datepicker.min.css?ver=facturis-online-sync/View/vanillajs-datepicker/dist/css/datepicker-bs4.min.css?ver=facturis-online-sync/View/vanillajs-datepicker/dist/js/datepicker-full.min.js?ver=facturis-online-sync/View/js/tab1.js?ver=facturis-online-sync/View/js/tab2.js?ver=facturis-online-sync/View/js/tab3.js?ver=facturis-online-sync/View/js/tab4.js?ver=facturis-online-sync/View/js/tab5.js?ver=HTML / DOM Fingerprints
facturis-sync-admin-wrapperfacturis-sync-admin-sidebarfacturis-sync-admin-contentfacturis-sync-admin-logofacturis-sync-admin-tabs-wrapperfacturis-sync-admin-tabfacturis-sync-admin-tab-activefacturis-sync-tab-content+4 more<!-- FACTURIS ONLINE SYNC START --><!-- FACTURIS ONLINE SYNC END --><!-- facturis-sync-admin-menu --><!-- facturis-sync-admin-content -->data-facturis-sync-tabdata-facturis-sync-actionFacturisSyncAjaxfacturisSyncTabsfacturisSyncDatePicker/wp-json/facturis-online-sync/v1/test-auth/wp-json/facturis-online-sync/v1/get-gestiuni/wp-json/facturis-online-sync/v1/check-version/wp-json/facturis-online-sync/v1/add-proforma/wp-json/facturis-online-sync/v1/view-proforma/wp-json/facturis-online-sync/v1/add-invoice/wp-json/facturis-online-sync/v1/view-invoice