
Invelity iKros Invoices Security & Risk Analysis
wordpress.org/plugins/invelity-ikros-invoicesPlugin Invelity iKros invoices is designed for Wordpress (WooCommerce) online stores who have purchased invoicing software iKros.
Is Invelity iKros Invoices Safe to Use in 2026?
Generally Safe
Score 85/100Invelity iKros Invoices has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "invelity-ikros-invoices" plugin v1.3.3 exhibits a mixed security posture. On the positive side, it demonstrates good practices by avoiding common entry points like AJAX handlers, REST API routes, shortcodes, and cron events without authentication or permission checks. Furthermore, all SQL queries utilize prepared statements, and there's a moderate number of nonces and capability checks present. However, the static analysis reveals significant concerns. The presence of the `unserialize` function, a known source of vulnerabilities if not handled with extreme care, is a critical warning sign. This is compounded by a high severity taint flow with an unsanitized path, indicating a potential pathway for malicious input to be processed without proper validation. The limited output escaping (62%) also suggests a risk of cross-site scripting (XSS) vulnerabilities. The plugin's vulnerability history being entirely clean is a positive indicator, but it does not negate the risks identified in the static analysis. The lack of recorded vulnerabilities could be due to lack of widespread use, insufficient auditing, or simply good fortune. In conclusion, while the plugin avoids common attack vectors, the identified code signals like `unserialize` and the high severity taint flow, coupled with insufficient output escaping, present tangible security risks that require immediate attention and remediation.
Key Concerns
- High severity unsanitized taint flow detected
- Use of dangerous function: unserialize
- Low percentage of properly escaped output
Invelity iKros Invoices Security Vulnerabilities
Invelity iKros Invoices Release Timeline
Invelity iKros Invoices Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Invelity iKros Invoices Attack Surface
WordPress Hooks 11
Maintenance & Trust
Invelity iKros Invoices Maintenance & Trust
Maintenance Signals
Community Trust
Invelity iKros Invoices Alternatives
PDF Invoices & Packing Slips for WooCommerce
woocommerce-pdf-invoices-packing-slips
Create, print & automatically email PDF or XML Invoices & PDF Packing Slips for WooCommerce orders.
WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels
print-invoices-packing-slip-labels-for-woocommerce
Auto-generate and attach WooCommerce PDF invoices and packing slips to order emails with customizable templates & bulk print options.
Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools
woocommerce-jetpack
Supercharge WooCommerce with FREE Abandoned Cart Recovery, Product Variation Swatches, PDF Invoices & 100+ tools. Boost sales & save time.
Invoices for WooCommerce
woocommerce-pdf-invoices
Automatically generate and attach customizable PDF Invoices and PDF Packing Slips for WooCommerce to emails.
Flexible PDF Invoices for WooCommerce & WordPress
flexible-invoices
WooCommerce PDF invoices made simple. EU VAT validation, reverse charge invoice, proforma invoices, MOSS / OSS support, invoices in bulk and more.
Invelity iKros Invoices Developer Profile
9 plugins · 430 total installs
How We Detect Invelity iKros Invoices
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/invelity-ikros-invoices/assets/css/invelity-ikros-invoices-admin.css/wp-content/plugins/invelity-ikros-invoices/assets/js/invelity-ikros-invoices-admin.js/wp-content/plugins/invelity-ikros-invoices/assets/js/invelity-ikros-invoices-admin.jsinvelity-ikros-invoices/assets/css/invelity-ikros-invoices-admin.css?ver=invelity-ikros-invoices/assets/js/invelity-ikros-invoices-admin.js?ver=HTML / DOM Fingerprints
invelity-plugins<!-- Download invoice PDF --><!-- Faktúra k vašej objednávke č. -->data-post-id