
Yesh Invoice Payment Gateway for WooCommerce Security & Risk Analysis
wordpress.org/plugins/invoice-gateway-yeshinvoiceYesh Invoice plugin allows you to send automatic invoices for any transaction on your yourWooCommerce. Enjoy a variety of useful features, such as Bit …
Is Yesh Invoice Payment Gateway for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Yesh Invoice Payment Gateway for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "invoice-gateway-yeshinvoice" plugin v1.5.4 exhibits a mixed security posture. On the positive side, there are no registered CVEs, and the static analysis shows no identified dangerous functions, a low number of file operations, and a high percentage of properly escaped output. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. However, several concerning areas require attention.
The plugin's SQL queries are a significant weakness. All three identified SQL queries are not using prepared statements, which presents a high risk of SQL injection vulnerabilities, especially given that taint analysis revealed flows with unsanitized paths. While no critical or high-severity taint flows were explicitly flagged, the presence of unsanitized paths in conjunction with raw SQL queries is a substantial concern. Furthermore, the complete lack of nonce and capability checks for any entry points, although the current attack surface is zero, means that if new entry points are added in the future, they would be inherently insecure.
The vulnerability history is clean, with no recorded CVEs. This is a positive indicator and might suggest diligent maintenance or a lack of past exploitable flaws. However, the raw SQL and unsanitized path findings are significant enough to warrant caution. The plugin's strengths lie in its limited attack surface and good output escaping. The primary weaknesses are the unescaped SQL queries and the potential for unsanitized path issues, which could be exploited if new entry points are introduced without proper security measures.
Key Concerns
- SQL queries without prepared statements
- Taint flows with unsanitized paths
- No nonce checks
- No capability checks
Yesh Invoice Payment Gateway for WooCommerce Security Vulnerabilities
Yesh Invoice Payment Gateway for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Yesh Invoice Payment Gateway for WooCommerce Attack Surface
WordPress Hooks 24
Maintenance & Trust
Yesh Invoice Payment Gateway for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Yesh Invoice Payment Gateway for WooCommerce Alternatives
Yesh Invoice Invoices for WooCommerce
yesh-invoice-invoices-for-woocommerce
Yesh Invoice plugin allows you to send automatic invoices for any transaction on your yourWooCommerce. Enjoy a variety of useful features, such as Bit …
PDF Invoices & Packing Slips for WooCommerce
woocommerce-pdf-invoices-packing-slips
Create, print & automatically email PDF or XML Invoices & PDF Packing Slips for WooCommerce orders.
WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels
print-invoices-packing-slip-labels-for-woocommerce
Auto-generate and attach WooCommerce PDF invoices and packing slips to order emails with customizable templates & bulk print options.
Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools
woocommerce-jetpack
Supercharge WooCommerce with FREE Abandoned Cart Recovery, Product Variation Swatches, PDF Invoices & 100+ tools. Boost sales & save time.
Invoices for WooCommerce
woocommerce-pdf-invoices
Automatically generate and attach customizable PDF Invoices and PDF Packing Slips for WooCommerce to emails.
Yesh Invoice Payment Gateway for WooCommerce Developer Profile
2 plugins · 60 total installs
How We Detect Yesh Invoice Payment Gateway for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/invoice-gateway-yeshinvoice/js/yeshinvoice.js/wp-content/plugins/invoice-gateway-yeshinvoice/css/yeshinvoice.css/wp-content/plugins/invoice-gateway-yeshinvoice/js/yeshinvoice.jsinvoice-gateway-yeshinvoice/js/yeshinvoice.js?ver=invoice-gateway-yeshinvoice/css/yeshinvoice.css?ver=HTML / DOM Fingerprints
custom-iframeid="custom-iframe"name="custom-iframe"data-yeshin-target="custom-iframe"window.custom_iframewindow.YESHIN_CONFIG/wp-json/wc-yeshin/v1/some_endpoint[yeshinvoice_payment_form]