
Yesh Invoice – WooCommerce Payment Gateway Security & Risk Analysis
wordpress.org/plugins/invoice-gateway-yeshinvoiceYesh Invoice (יש חשבונית) adds a secure payment gateway and automatic invoices, receipts and accounting documents to WooCommerce.
Is Yesh Invoice – WooCommerce Payment Gateway Safe to Use in 2026?
Generally Safe
Score 100/100Yesh Invoice – WooCommerce Payment Gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "invoice-gateway-yeshinvoice" plugin v1.5.4 exhibits a mixed security posture. On the positive side, there are no registered CVEs, and the static analysis shows no identified dangerous functions, a low number of file operations, and a high percentage of properly escaped output. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. However, several concerning areas require attention.
The plugin's SQL queries are a significant weakness. All three identified SQL queries are not using prepared statements, which presents a high risk of SQL injection vulnerabilities, especially given that taint analysis revealed flows with unsanitized paths. While no critical or high-severity taint flows were explicitly flagged, the presence of unsanitized paths in conjunction with raw SQL queries is a substantial concern. Furthermore, the complete lack of nonce and capability checks for any entry points, although the current attack surface is zero, means that if new entry points are added in the future, they would be inherently insecure.
The vulnerability history is clean, with no recorded CVEs. This is a positive indicator and might suggest diligent maintenance or a lack of past exploitable flaws. However, the raw SQL and unsanitized path findings are significant enough to warrant caution. The plugin's strengths lie in its limited attack surface and good output escaping. The primary weaknesses are the unescaped SQL queries and the potential for unsanitized path issues, which could be exploited if new entry points are introduced without proper security measures.
Key Concerns
- SQL queries without prepared statements
- Taint flows with unsanitized paths
- No nonce checks
- No capability checks
Yesh Invoice – WooCommerce Payment Gateway Security Vulnerabilities
Yesh Invoice – WooCommerce Payment Gateway Release Timeline
Yesh Invoice – WooCommerce Payment Gateway Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Yesh Invoice – WooCommerce Payment Gateway Attack Surface
WordPress Hooks 24
Maintenance & Trust
Yesh Invoice – WooCommerce Payment Gateway Maintenance & Trust
Maintenance Signals
Community Trust
Yesh Invoice – WooCommerce Payment Gateway Alternatives
Invoice Gateway for WooCommerce – Invoice Payment Gateway
invoice-gateway-for-woocommerce
Add a WooCommerce invoice gateway to your store. An easy invoicing payment gateway solution for WooCommerce.
Peki – Fiken Integration for WooCommerce
peki-fiken-integration-for-woocommerce
Automate your bookkeeping by connecting WooCommerce to Fiken. Export orders automatically and save time on manual accounting tasks.
Invoct – PDF Invoices & Billing for WooCommerce
kirilkirkov-pdf-invoice-manager
Professional PDF invoicing & billing for WooCommerce and WordPress, with Stripe payments and automated VAT/tax handling.
Peki – Bokio Integration for WooCommerce
peki-bokio-integration-for-woocommerce
Connect WooCommerce to Bokio to export orders automatically and keep ledgers, VAT, and documentation in sync.
Peki Tripletex Integration for WooCommerce
peki-tripletex-integration-for-woocommerce
Integrate WooCommerce with Tripletex. Automatically transfer orders and refunds to Tripletex via the Peki service. Learn more on our Tripletex plugin …
Yesh Invoice – WooCommerce Payment Gateway Developer Profile
2 plugins · 70 total installs
How We Detect Yesh Invoice – WooCommerce Payment Gateway
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/invoice-gateway-yeshinvoice/js/yeshinvoice.js/wp-content/plugins/invoice-gateway-yeshinvoice/css/yeshinvoice.css/wp-content/plugins/invoice-gateway-yeshinvoice/js/yeshinvoice.jsinvoice-gateway-yeshinvoice/js/yeshinvoice.js?ver=invoice-gateway-yeshinvoice/css/yeshinvoice.css?ver=HTML / DOM Fingerprints
custom-iframeid="custom-iframe"name="custom-iframe"data-yeshin-target="custom-iframe"window.custom_iframewindow.YESHIN_CONFIG/wp-json/wc-yeshin/v1/some_endpoint[yeshinvoice_payment_form]