
Fiscomm PURS E-Fiscalisation Security & Risk Analysis
wordpress.org/plugins/fiscomm-purs-e-fiscalisationWooCommerce connector for the Fiscomm E-Fiscalization API — automatically fiscalise Serbian Tax Authority (PURS) invoices on order completion.
Is Fiscomm PURS E-Fiscalisation Safe to Use in 2026?
Generally Safe
Score 100/100Fiscomm PURS E-Fiscalisation has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "fiscomm-purs-e-fiscalisation" v0.1.4 plugin exhibits a strong security posture based on the provided static analysis and vulnerability history. The plugin has zero recorded CVEs, indicating a history of responsible development or limited exposure. Statistically, the code demonstrates good practices with a high percentage of properly escaped outputs and 100% of SQL queries using prepared statements. The absence of dangerous functions, file operations, external HTTP requests, and a clean taint analysis further bolsters this positive outlook. A significant strength is the zero attack surface from common entry points like AJAX handlers, REST API routes, and shortcodes, and the presence of capability checks for the one identified entry point. The bundled Guzzle library, while a potential concern for outdated versions, is noted as a bundled library and not inherently a vulnerability.
However, the complete lack of nonce checks across any entry points is a notable concern. While the attack surface is currently zero, any future addition of AJAX handlers, for instance, without the implementation of nonce checks, would introduce a significant Cross-Site Request Forgery (CSRF) vulnerability. The plugin's current security is heavily reliant on its minimal attack surface rather than explicit defense mechanisms against common web vulnerabilities like CSRF. Therefore, while the plugin appears secure at this moment, future development must prioritize implementing nonce checks for any interactive features to maintain this security level.
Key Concerns
- No nonce checks implemented
Fiscomm PURS E-Fiscalisation Security Vulnerabilities
Fiscomm PURS E-Fiscalisation Release Timeline
Fiscomm PURS E-Fiscalisation Code Analysis
Bundled Libraries
Output Escaping
Fiscomm PURS E-Fiscalisation Attack Surface
WordPress Hooks 19
Maintenance & Trust
Fiscomm PURS E-Fiscalisation Maintenance & Trust
Maintenance Signals
Community Trust
Fiscomm PURS E-Fiscalisation Alternatives
Wooplatnica
wooplatnica
WooCommerce payment gateway za generisanje opštih uplatnica i NBS IPS QR kôdova za uplate iz Srbije. 🇷🇸
KigoKasa Fiscalization for WooCommerce
kigokasa-api-for-woocommerce
This plugin provides integration of KigoKasa service with WooCommerce webshop.
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 120+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
WooPayments: Integrated WooCommerce Payments
woocommerce-payments
Securely accept credit and debit cards on your WooCommerce store. Manage payments without leaving your WordPress dashboard. Only with WooPayments.
Google for WooCommerce
google-listings-and-ads
Native integration with Google that allows merchants to easily display their products across Google’s network.
Fiscomm PURS E-Fiscalisation Developer Profile
1 plugin · 100 total installs
How We Detect Fiscomm PURS E-Fiscalisation
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/fiscomm-purs-e-fiscalisation/assets/css/style.css/wp-content/plugins/fiscomm-purs-e-fiscalisation/assets/js/script.js/wp-content/plugins/fiscomm-purs-e-fiscalisation/assets/js/script.jsfiscomm-purs-e-fiscalisation/assets/css/style.css?ver=fiscomm-purs-e-fiscalisation/assets/js/script.js?ver=HTML / DOM Fingerprints
fiscomm-purs-e-fiscalisation-settings<!-- FISCOMM PURS E-FISCALISATION WooCommerce Plugin -->data-fiscal-statusdata-fiscal-iddata-fiscomm-order-idfiscomm_vars