Filogy Invoice Security & Risk Analysis

wordpress.org/plugins/filogy-invoice

Create wonderful financial documents like orders, invoices, delivery notes for your customers right in your WooCommerce webstore.

0 active installs v1.1.9 PHP + WP 3.8+ Updated Unknown
delivery-noteinvoicepdfpdf-invoiceprint
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Filogy Invoice Safe to Use in 2026?

Generally Safe

Score 100/100

Filogy Invoice has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The filogy-invoice plugin exhibits a generally strong security posture, with a promising absence of known vulnerabilities and robust implementation of security best practices like prepared statements for SQL queries and a good number of nonce and capability checks. The static analysis indicates a relatively small attack surface, with no unprotected entry points identified in AJAX handlers or REST API routes.

However, a significant concern arises from the taint analysis, which revealed 8 flows with unsanitized paths out of 10 analyzed. While no critical or high severity issues were flagged in the taint analysis, unsanitized paths can still lead to vulnerabilities like directory traversal or information disclosure if not handled carefully downstream. Furthermore, the output escaping rate is relatively low at 32%, suggesting a potential for Cross-Site Scripting (XSS) vulnerabilities in outputs that are not properly escaped. The presence of the dompdf library, while not inherently problematic, warrants attention regarding its potential for vulnerabilities if not kept updated.

In conclusion, filogy-invoice benefits from a clean vulnerability history and good foundational security practices. The primary areas of concern are the unsanitized path flows identified in the taint analysis and the low percentage of properly escaped output, which present potential risks that need thorough investigation and mitigation, despite the lack of historically recorded CVEs.

Key Concerns

  • Unsanitized paths in taint analysis
  • Low output escaping rate
  • Bundled library (dompdf)
Vulnerabilities
None known

Filogy Invoice Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Filogy Invoice Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
46 prepared
Unescaped Output
351
163 escaped
Nonce Checks
7
Capability Checks
7
File Operations
48
External Requests
3
Bundled Libraries
1

Bundled Libraries

dompdf

SQL Query Safety

96% prepared48 total queries

Output Escaping

32% escaped514 total outputs
Data Flows
8 unsanitized

Data Flow Analysis

10 flows8 with unsanitized paths
account_before_trash_post (includes\class-filo-initial-functions.php:423)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Filogy Invoice Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[filogy_doc] includes\class-filo-initial-functions.php:84
[filogy_doc_show_if] includes\class-filo-initial-functions.php:85
WordPress Hooks 120
actionplugins_loadedfilogy-framework-mini\filogy-framework.php:310
actionadmin_noticesfilogy-framework-mini\filogy-framework.php:324
actionadmin_noticesfilogy-framework-mini\filogy-framework.php:331
actioninitfilogy-framework-mini\filogy-framework.php:436
actionwp_enqueue_scriptsfilogy-framework-mini\includes\abstracts\abstract-filo-document.php:158
actioninitfilogy-framework-mini\includes\admin\class-filo-admin-fw.php:25
actioncurrent_screenfilogy-framework-mini\includes\admin\class-filo-admin-fw.php:26
actionadmin_footerfilogy-framework-mini\includes\admin\class-filo-admin-fw.php:27
filterfilo_report_urlfilogy-framework-mini\includes\admin\class-filo-admin-fw.php:40
filterfilo_output_fieldfilogy-framework-mini\includes\admin\filo-meta-box-functions.php:509
filterwoocommerce_order_classfilogy-framework-mini\includes\class-filo-order-factory.php:24
actionfilo_document_headfilogy-framework-mini\includes\filo_generate_pdf.php:54
actionplugins_loadedfilogy.php:328
filtercustomize_loaded_componentsfilogy.php:333
actionadmin_noticesfilogy.php:359
actionadmin_noticesfilogy.php:366
actioninitfilogy.php:568
actioninitfilogy.php:569
filterwoocommerce_email_actionsfilogy.php:587
actionadmin_enqueue_scriptsincludes\admin\class-filo-admin-assets.php:25
actionadmin_enqueue_scriptsincludes\admin\class-filo-admin-assets.php:26
actionwoocommerce_admin_order_actions_endincludes\admin\class-filo-admin-finadoc-list-table.php:34
actionadmin_menuincludes\admin\class-filo-admin-menus.php:21
actionadmin_headincludes\admin\class-filo-admin-menus.php:23
actionadd_meta_boxesincludes\admin\class-filo-admin-meta-boxes.php:29
actionadd_custom_page_meta_boxesincludes\admin\class-filo-admin-meta-boxes.php:37
filterhide_custom_page_menuincludes\admin\class-filo-admin-meta-boxes.php:38
actionsave_postincludes\admin\class-filo-admin-meta-boxes.php:43
actionadmin_noticesincludes\admin\class-filo-admin-meta-boxes.php:92
actionwoocommerce_product_after_variable_attributesincludes\admin\class-filo-admin-meta-boxes.php:150
actionadmin_print_stylesincludes\admin\class-filo-admin-notices.php:22
actionadmin_noticesincludes\admin\class-filo-admin-notices.php:58
filtermanage_users_columnsincludes\admin\class-filo-admin-partner-list-table.php:28
filtermanage_users_custom_columnincludes\admin\class-filo-admin-partner-list-table.php:29
filtermanage_users_sortable_columnsincludes\admin\class-filo-admin-partner-list-table.php:32
filterpre_user_queryincludes\admin\class-filo-admin-partner-list-table.php:35
filteruser_row_actionsincludes\admin\class-filo-admin-partner-list-table.php:38
actioninitincludes\admin\class-filo-admin.php:23
filterwoocommerce_get_settings_pagesincludes\admin\class-filo-admin.php:27
actionwoocommerce_admin_field_html_codeincludes\admin\class-filo-admin.php:28
actionwoocommerce_admin_field_date_pickerincludes\admin\class-filo-admin.php:29
actionwoocommerce_settings_startincludes\admin\class-filo-admin.php:33
actionwoocommerce_order_actions_endincludes\admin\class-filo-admin.php:35
filteradmin_body_classincludes\admin\class-filo-admin.php:39
filterwoocommerce_admin_order_preview_get_order_detailsincludes\admin\class-filo-admin.php:42
filterwoocommerce_admin_order_actionsincludes\admin\list-tables\class-filo-admin-list-table-finadoc.php:45
filterfilo_meta_box_shop_order_data_fieldsincludes\admin\meta-boxes\views\html-specialize-shop-order-head-data.php:14
actionfilo_admin_shop_order_head_data_beforeincludes\admin\meta-boxes\views\html-specialize-shop-order-head-data.php:17
filterwoocommerce_settings_tabs_arrayincludes\admin\settings\class-filo-settings-documents.php:26
filterwoocommerce_admin_billing_fieldsincludes\admin\settings\class-filo-settings-documents.php:31
filterwoocommerce_settings_tabs_arrayincludes\admin\settings\class-filo-settings-financials.php:39
actionadmin_initincludes\class-filo-do-setup.php:26
actionfilo_activationincludes\class-filo-do-setup.php:36
actioninitincludes\class-filo-do-setup.php:378
actioninitincludes\class-filo-documents.php:18
actionfilo_document_headerincludes\class-filo-documents.php:22
actionfilo_document_footerincludes\class-filo-documents.php:23
filterwoocommerce_localisation_address_formatsincludes\class-filo-financial-document.php:1807
filterwoocommerce_localisation_address_formatsincludes\class-filo-financial-document.php:1815
filterwoocommerce_localisation_address_formatsincludes\class-filo-financial-document.php:1828
actionadmin_menuincludes\class-filo-initial-functions.php:28
actionadmin_headincludes\class-filo-initial-functions.php:29
filterwoocommerce_screen_idsincludes\class-filo-initial-functions.php:35
actionuser_edit_form_tagincludes\class-filo-initial-functions.php:57
actionuser_edit_form_tagincludes\class-filo-initial-functions.php:58
actionpersonal_options_updateincludes\class-filo-initial-functions.php:60
actionedit_user_profile_updateincludes\class-filo-initial-functions.php:61
filteruser_admin_urlincludes\class-filo-initial-functions.php:65
filteradmin_urlincludes\class-filo-initial-functions.php:66
filternetwork_admin_urlincludes\class-filo-initial-functions.php:67
filterwoocommerce_customer_meta_fieldsincludes\class-filo-initial-functions.php:68
actionwoocommerce_checkout_update_order_metaincludes\class-filo-initial-functions.php:74
actionwoocommerce_admin_order_data_after_order_detailsincludes\class-filo-initial-functions.php:77
filterwoocommerce_order_numberincludes\class-filo-initial-functions.php:82
actionfilogy_after_initial_functionsincludes\class-filo-initial-functions.php:91
filterquery_varsincludes\class-filo-initial-functions.php:92
filterwp_headersincludes\class-filo-initial-functions.php:93
actiontemplate_redirectincludes\class-filo-initial-functions.php:94
filteradmin_footer_textincludes\class-filo-initial-functions.php:343
filterupdate_footerincludes\class-filo-initial-functions.php:344
filterwoocommerce_my_account_my_orders_actionsincludes\class-filo-myaccount.php:17
actioninitincludes\class-filo-post-types.php:24
actioninitincludes\class-filo-post-types.php:26
actioninitincludes\class-filo-post-types.php:27
actioninitincludes\class-filo-post-types.php:29
filterwoocommerce_register_post_type_shop_orderincludes\class-filo-post-types.php:31
filterwoocommerce_screen_idsincludes\class-filo-post-types.php:33
actionwoocommerce_check_cart_itemsincludes\class-filo-post-types.php:37
actionwp_footer_filoincludes\customize\class-filo-customize-manager.php:3748
actionwp_footer_filoincludes\customize\class-filo-customize-manager.php:3749
actionwp_footer_filoincludes\customize\class-filo-customize-manager.php:5541
actioncustomize_registerincludes\customize\class-filo-customize-manager.php:5840
actioncustomize_controls_print_footer_scriptsincludes\customize\class-filo-customize-manager.php:5842
actioncustomize_controls_print_footer_scriptsincludes\customize\class-filo-customize-manager.php:5844
actioncustomize_controls_print_footer_scriptsincludes\customize\class-filo-customize-manager.php:5845
actioncustomize_controls_print_footer_scriptsincludes\customize\class-filo-customize-manager.php:5846
actioncustomize_controls_print_footer_scriptsincludes\customize\class-filo-customize-manager.php:5847
actioncustomize_controls_print_footer_scriptsincludes\customize\class-filo-customize-manager.php:5849
actioncustomize_preview_initincludes\customize\class-filo-customize-manager.php:5853
actioncustomize_save_afterincludes\customize\class-filo-customize-manager.php:5855
actionwp_footer_filoincludes\customize\class-filo-customize-manager.php:5858
actionwp_footer_filoincludes\customize\class-filo-customize-manager.php:5859
actionwp_loadedincludes\customize\class-filo-customize-manager.php:5860
filtersiteorigin_panels_css_row_gutterincludes\customize\class-filo-customize-manager.php:5862
filtersiteorigin_panels_css_row_margin_bottomincludes\customize\class-filo-customize-manager.php:5863
actionwp_enqueue_scriptsincludes\customize\class-filo-customize-manager.php:5866
actionadmin_enqueue_scriptsincludes\customize\class-filo-customize-manager.php:5867
actionwp_print_scriptsincludes\customize\class-filo-customize-manager.php:5869
filterfilo_customize_section_descriptionincludes\customize\class-filo-customize-manager.php:5870
filterfilo_generate_filo_sa_deliv_note_documentincludes\documents\class-filo-document-sa-deliv-note.php:28
filterfilo_settings_document_filo_sa_deliv_note_data_fieldsincludes\documents\class-filo-document-sa-deliv-note.php:31
filterfilo_generate_filo_sa_invoice_documentincludes\documents\class-filo-document-sa-invoice.php:28
filterfilo_settings_document_filo_sa_invoice_data_fieldsincludes\documents\class-filo-document-sa-invoice.php:31
filterfilo_generate_shop_order_documentincludes\documents\class-filo-document-shop-order.php:31
filterfilo_settings_document_shop_order_data_fieldsincludes\documents\class-filo-document-shop-order.php:34
actionfilo_doc_customizer_add_template_custom_settingstemplates\00_filogy_original\documents\template_custom_settings.php:23
actionfilo_doc_customizer_add_template_custom_settingstemplates\01_filogy_standard\documents\template_custom_settings.php:97
filterwoocommerce_settings_tabs_arraytemplates\documents\class-filo-settings-documents-style.php:27
filterwoocommerce_localisation_address_formatstemplates\documents\document-standard-begin.php:53
actionfilo_register_document_templatetemplates\documents\filo_register_document_template.php:57
Maintenance & Trust

Filogy Invoice Maintenance & Trust

Maintenance Signals

WordPress version tested5.6.17
Last updatedUnknown
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Filogy Invoice Developer Profile

WebshopLogic

4 plugins · 6K total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Filogy Invoice

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/filogy-invoice/assets/css/invoice.css/wp-content/plugins/filogy-invoice/assets/css/print.css/wp-content/plugins/filogy-invoice/assets/js/filogy-invoice.js/wp-content/plugins/filogy-invoice/assets/js/filogy-invoice-public.js/wp-content/plugins/filogy-invoice/modules/dompdf/css/bootstrap.min.css/wp-content/plugins/filogy-invoice/modules/dompdf/css/invoice.css
Script Paths
/wp-content/plugins/filogy-invoice/assets/js/filogy-invoice.js/wp-content/plugins/filogy-invoice/assets/js/filogy-invoice-public.js
Version Parameters
/wp-content/plugins/filogy-invoice/assets/css/invoice.css?ver=/wp-content/plugins/filogy-invoice/assets/css/print.css?ver=/wp-content/plugins/filogy-invoice/assets/js/filogy-invoice.js?ver=/wp-content/plugins/filogy-invoice/assets/js/filogy-invoice-public.js?ver=/wp-content/plugins/filogy-invoice/modules/dompdf/css/bootstrap.min.css?ver=/wp-content/plugins/filogy-invoice/modules/dompdf/css/invoice.css?ver=

HTML / DOM Fingerprints

CSS Classes
filogy-invoice-wrapfilogy-invoice-containerfilogy-invoice-formfilogy-invoice-submitfilogy-invoice-previewfilogy-invoice-print-buttonfilogy-invoice-add-item-button
HTML Comments
<!-- FILOGY INVOICE START --><!-- FILOGY INVOICE END -->
Data Attributes
data-filogy-invoice-iddata-filogy-invoice-nonce
JS Globals
filogy_invoice_params
Shortcode Output
[filogy_invoice_form][filogy_invoice_preview][filogy_invoice_list]
FAQ

Frequently Asked Questions about Filogy Invoice