
Invoice On The Go Security & Risk Analysis
wordpress.org/plugins/invoice-on-the-goCreate invoices anywhere (and in seconds) using your phone!
Is Invoice On The Go Safe to Use in 2026?
Generally Safe
Score 85/100Invoice On The Go has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "invoice-on-the-go" v1.0 plugin exhibits a mixed security posture. While it demonstrates good practices in SQL query preparation and output escaping, significant concerns arise from its attack surface and taint analysis. The presence of multiple unprotected AJAX handlers and a REST API route without permission callbacks represents a substantial risk, as these entry points could be exploited by unauthenticated users. The taint analysis revealing two high-severity flows with unsanitized paths further exacerbates this, suggesting potential for code execution or data manipulation if these paths are triggered with malicious input.
The plugin's vulnerability history is a positive sign, with no recorded CVEs. This indicates a generally stable codebase or perhaps a lack of public scrutiny thus far. However, this lack of history should not overshadow the critical flaws identified in the static analysis. The strengths lie in its diligent use of prepared statements for SQL and robust output escaping, which mitigates common web vulnerabilities. Conversely, the weaknesses are stark, primarily centered around the lack of authentication and authorization checks on critical entry points, coupled with the identified high-severity taint flows.
Key Concerns
- Unprotected AJAX handlers
- REST API route without permission callbacks
- High severity taint flows
- No nonce checks
Invoice On The Go Security Vulnerabilities
Invoice On The Go Release Timeline
Invoice On The Go Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Invoice On The Go Attack Surface
AJAX Handlers 3
REST API Routes 1
Shortcodes 1
WordPress Hooks 11
Scheduled Events 1
Maintenance & Trust
Invoice On The Go Maintenance & Trust
Maintenance Signals
Community Trust
Invoice On The Go Alternatives
PDF Invoices & Packing Slips for WooCommerce
woocommerce-pdf-invoices-packing-slips
Create, print & automatically email PDF or XML Invoices & PDF Packing Slips for WooCommerce orders.
WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels
print-invoices-packing-slip-labels-for-woocommerce
Auto-generate and attach WooCommerce PDF invoices and packing slips to order emails with customizable templates & bulk print options.
Print Invoice & Delivery Notes for WooCommerce
woocommerce-delivery-notes
Create and print PDF invoices, delivery notes and receipts for your WooCommerce orders. Choose your document format from multiple templates.
Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools
woocommerce-jetpack
Supercharge WooCommerce with FREE Abandoned Cart Recovery, Product Variation Swatches, PDF Invoices & 100+ tools. Boost sales & save time.
Invoices for WooCommerce
woocommerce-pdf-invoices
Automatically generate and attach customizable PDF Invoices and PDF Packing Slips for WooCommerce to emails.
Invoice On The Go Developer Profile
19 plugins · 12K total installs
How We Detect Invoice On The Go
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/invoice-on-the-go/assets/css/admin/invoice-style.css/wp-content/plugins/invoice-on-the-go/assets/css/style.css/wp-content/plugins/invoice-on-the-go/assets/js/admin/invoice-admin.js/wp-content/plugins/invoice-on-the-go/assets/js/invoice.js/wp-content/plugins/invoice-on-the-go/assets/js/payment.js/wp-content/plugins/invoice-on-the-go/assets/js/admin/invoice-admin.js/wp-content/plugins/invoice-on-the-go/assets/js/invoice.js/wp-content/plugins/invoice-on-the-go/assets/js/payment.jsinvoice-on-the-go/assets/css/admin/invoice-style.css?ver=invoice-on-the-go/assets/css/style.css?ver=invoice-on-the-go/assets/js/admin/invoice-admin.js?ver=invoice-on-the-go/assets/js/invoice.js?ver=invoice-on-the-go/assets/js/payment.js?ver=HTML / DOM Fingerprints
rniotg-invoice-formrniotg-payment-formrednao-invoice-on-the-godata-invoice-iddata-invoice-numberrniotg_payment_settingsrniotg_invoice_settings/wp-json/rniotg/v1/invoice/wp-json/rniotg/v1/payment[rniotg_payment][rniotg_invoice]