
FreeInvoice API Security & Risk Analysis
wordpress.org/plugins/freeinvoice-apiPlugin di FreeInvoice per la fatturazione elettronica con WooCommerce.
Is FreeInvoice API Safe to Use in 2026?
Generally Safe
Score 92/100FreeInvoice API has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'freeinvoice-api' v1.0.3 plugin exhibits a concerning security posture due to a significant lack of proper authentication and authorization checks, particularly within its AJAX handlers. With one AJAX handler identified as lacking authentication, this presents a direct and easily exploitable attack vector. While the absence of critical or high-severity taint flows is positive, the low percentage of properly escaped output (24%) suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities across various output points. The presence of raw SQL queries (75% not using prepared statements) further heightens the risk of SQL injection attacks. The plugin's vulnerability history is clean, with no recorded CVEs, which could indicate a history of secure development or simply a lack of in-depth auditing. However, the current static analysis findings reveal fundamental security weaknesses that must be addressed.
Key Concerns
- AJAX handler without authentication
- Low percentage of properly escaped output
- High percentage of SQL queries without prepared statements
- No capability checks found
FreeInvoice API Security Vulnerabilities
FreeInvoice API Code Analysis
SQL Query Safety
Output Escaping
FreeInvoice API Attack Surface
AJAX Handlers 1
WordPress Hooks 18
Maintenance & Trust
FreeInvoice API Maintenance & Trust
Maintenance Signals
Community Trust
FreeInvoice API Alternatives
WooCompany015
woocompany015
Plugin ufficiale WooCompany015, attiva l'integrazione degli ordini ricevuti sul sito WooCommerce con il gestionale COMPANY015 https://www.
POP – Free European electronic invoicing for e-commerce (ex-WooPop)
woopop-electronic-invoice-free
Automate European e-invoicing for e-commerce: generate XML & PDF invoices, send via SdI and PEPPOL, manage compliance with API credits.
WFatture for WooCommerce Fattureincloud
woo-fattureincloud
WooCommerce Fattureincloud by Woofatture trasforma gli ordini in fatture su fattureincloud.it WFatture for WooCommerce Fattureincloud
Fattura24
fattura24
The official Fattura24 plugin allows the creation of electronic invoices, orders, traditional invoices and receipts via Fattura24
Partita Iva per Fattura Elettronica
partita-iva-per-fattura-elettronica
Description: Partita Iva per Fattura Elettronica adds to the Woocommerce standard checkout form some custom fields(VAT Number, Fiscal Code, NIN Code a …
FreeInvoice API Developer Profile
1 plugin · 10 total installs
How We Detect FreeInvoice API
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/freeinvoice-api/admin/css/freeinvoice-api-admin.css/wp-content/plugins/freeinvoice-api/admin/js/freeinvoice-api-admin.js/wp-content/plugins/freeinvoice-api/admin/js/freeinvoice-api-admin.jsfreeinvoice-api/admin/css/freeinvoice-api-admin.css?ver=freeinvoice-api/admin/js/freeinvoice-api-admin.js?ver=