Indian GST Invoice Suite Security & Risk Analysis

wordpress.org/plugins/indian-gst-invoice-suite

Generate GST Compliant PDF invoices, Supports CGST/SGST/IGST, HSN/SAC, and more for WooCommerce.

20 active installs v1.2.1 PHP 8.2+ WP 5.0+ Updated Feb 14, 2026
gstgst-invoiceindian-gstindian-taxwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Indian GST Invoice Suite Safe to Use in 2026?

Generally Safe

Score 100/100

Indian GST Invoice Suite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "indian-gst-invoice-suite" v1.2.1 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events without proper authentication or permission checks significantly limits the direct attack surface. Furthermore, the low number of file operations and zero external HTTP requests are positive indicators. The plugin also demonstrates good practices by utilizing prepared statements for the majority of its SQL queries and performing output escaping on a high percentage of outputs, alongside a healthy number of nonce and capability checks. However, the presence of the bundled "dompdf" library warrants a degree of caution, as bundled libraries can sometimes be a vector for vulnerabilities if not kept up-to-date. The plugin's vulnerability history is clean, with no recorded CVEs, which suggests a history of secure development and maintenance. Overall, this plugin appears to be developed with security in mind, with a minimal attack surface and good internal coding practices. The primary area for potential concern lies in ensuring the bundled dompdf library is maintained and updated.

Key Concerns

  • Bundled library (dompdf)
Vulnerabilities
None known

Indian GST Invoice Suite Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Indian GST Invoice Suite Code Analysis

Dangerous Functions
0
Raw SQL Queries
9
38 prepared
Unescaped Output
57
244 escaped
Nonce Checks
20
Capability Checks
12
File Operations
3
External Requests
0
Bundled Libraries
1

Bundled Libraries

dompdf

SQL Query Safety

81% prepared47 total queries

Output Escaping

81% escaped301 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
<active-addons> (core\active-addons.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Indian GST Invoice Suite Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 56
actionadmin_initaddons\packing-slip\helper.php:58
actionindian_gst_render_packing_slip_buttonaddons\packing-slip\hook.php:58
actionwoocommerce_admin_order_data_after_order_detailsadmin\admin-hooks.php:13
actionindian_gst_woo_invoice_settings_tabsadmin\general-settings.php:13
actionadmin_noticesadmin\general-settings.php:157
actionadmin_initadmin\general-settings.php:208
filtermanage_edit-product_columnsadmin\layout.php:12
actionmanage_product_posts_custom_columnadmin\layout.php:38
filtermanage_edit-product_sortable_columnsadmin\layout.php:59
actioninitadmin\patch.php:13
filterwoocommerce_tax_settingsadmin\patch.php:25
actionadmin_enqueue_scriptsadmin\patch.php:35
filtergettextadmin\patch.php:59
actioninitcore\active-addons.php:18
actionadmin_post_indian_gst_toggle_addoncore\active-addons.php:23
actionplugins_loadedcore\active-addons.php:85
actionadmin_enqueue_scriptscore\enqueue.php:10
actionadmin_enqueue_scriptscore\enqueue.php:69
actionadmin_enqueue_scriptscore\enqueue.php:120
actionadmin_menucore\menu.php:10
actionadmin_initcore\notice.php:15
actionadmin_enqueue_scriptscore\notice.php:34
actionadmin_noticescore\notice.php:49
actionadmin_initcore\restore.php:13
actionadmin_noticescore\restore.php:66
actionadmin_noticescore\restore.php:135
actionquick_edit_custom_boxincludes\core.php:20
actionbulk_edit_custom_boxincludes\core.php:21
actionwoocommerce_process_product_metaincludes\core.php:34
actionwoocommerce_save_product_variationincludes\core.php:45
actionsave_post_productincludes\core.php:56
filterwoocommerce_my_account_my_orders_actionsincludes\frontend-hooks.php:13
actionadmin_initincludes\frontend-hooks.php:81
actionadmin_initincludes\functions.php:75
actionadmin_initincludes\functions.php:278
actionadmin_noticesincludes\functions.php:295
actionadmin_initincludes\functions.php:351
actionadmin_noticesincludes\functions.php:382
actionadmin_noticesincludes\functions.php:426
actionadmin_noticesincludes\functions.php:431
actionwoocommerce_admin_process_product_objectincludes\functions.php:454
actionwoocommerce_save_product_variationincludes\functions.php:478
actionwoocommerce_thankyouincludes\helper.php:39
actionadmin_initincludes\helper.php:131
actionadmin_enqueue_scriptsincludes\hsn.php:13
actionwoocommerce_product_options_taxincludes\hsn.php:49
actionwoocommerce_process_product_metaincludes\hsn.php:67
actionwoocommerce_variation_options_taxincludes\hsn.php:96
actionwoocommerce_save_product_variationincludes\hsn.php:118
actionwoocommerce_product_bulk_edit_endincludes\hsn.php:143
actionwoocommerce_product_bulk_edit_saveincludes\hsn.php:166
filtermanage_edit-product_columnsincludes\hsn.php:196
actionmanage_product_posts_custom_columnincludes\hsn.php:212
actionwoocommerce_product_quick_edit_endincludes\hsn.php:228
actionwoocommerce_product_quick_edit_saveincludes\hsn.php:248
actionplugins_loadedindian-gst-invoice-suite.php:28
Maintenance & Trust

Indian GST Invoice Suite Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedFeb 14, 2026
PHP min version8.2
Downloads476

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Indian GST Invoice Suite Developer Profile

SAUBHIK DAS

2 plugins · 20 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Indian GST Invoice Suite

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/indian-gst-invoice-suite/css/free-pslip.css

HTML / DOM Fingerprints

CSS Classes
titlestore-namesection-titlealign-centeralign-rightboldnote
HTML Comments
Important for reviewers: This CSS is loaded inline only because this file is used as an HTML template for PDF generation (via Dompdf). wp_enqueue_style() cannot be used here since it's not a browser-rendered page.
FAQ

Frequently Asked Questions about Indian GST Invoice Suite