
Kiwiz for WooCommerce Security & Risk Analysis
wordpress.org/plugins/kiwiz-invoices-certification-pdf-fileLe module Kiwiz est un système de certification en temps réel dans la Blockchain pour se conformer à la loi anti-fraude TVA 2018.
Is Kiwiz for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Kiwiz for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "kiwiz-invoices-certification-pdf-file" plugin version 2.2.1 exhibits a mixed security posture. On the positive side, it shows a strong commitment to secure coding practices with a high percentage of SQL queries using prepared statements and properly escaped output. The absence of known CVEs and a clean vulnerability history for this plugin are also very encouraging signs, suggesting a generally well-maintained codebase. The plugin also correctly implements nonce and capability checks in a significant portion of its code.
However, significant security concerns arise from the static analysis. The plugin has a single unprotected entry point in its AJAX handlers, creating a potential avenue for unauthorized actions if not properly secured elsewhere. While the taint analysis did not reveal critical or high-severity issues, the fact that all analyzed flows had "unsanitized paths" warrants attention, even if the immediate impact is not severe. The presence of bundled libraries like dompdf and TCPDF, while common for PDF generation, could introduce risks if they are outdated and contain unpatched vulnerabilities not yet reflected in the plugin's CVE history.
In conclusion, the plugin has foundational strengths in its coding practices and lack of historical vulnerabilities. Nevertheless, the unprotected AJAX handler and the indication of unsanitized paths in taint analysis present a clear and present risk that needs immediate remediation. The potential for bundled library vulnerabilities should also be monitored. Addressing these specific points would significantly improve the plugin's overall security.
Key Concerns
- Unprotected AJAX handler found
- All analyzed taint flows had unsanitized paths
- Bundled libraries (dompdf, TCPDF)
Kiwiz for WooCommerce Security Vulnerabilities
Kiwiz for WooCommerce Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Kiwiz for WooCommerce Attack Surface
AJAX Handlers 1
WordPress Hooks 62
Scheduled Events 1
Maintenance & Trust
Kiwiz for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Kiwiz for WooCommerce Alternatives
Paperdork voor WooCommerce
paperdork
Met de Paperdork plugin kun je jouw WooCommerce webshop automatisch koppelen aan je Paperdork boekhouding en automatiseer je je bestellingen.
EenvoudigFactureren for WooCommerce
eenvoudigfactureren-for-woocommerce
Generate invoices in EenvoudigFactureren for WooCommerce orders.
PDF Invoices & Packing Slips for WooCommerce
woocommerce-pdf-invoices-packing-slips
Create, print & automatically email PDF or XML Invoices & PDF Packing Slips for WooCommerce orders.
WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels
print-invoices-packing-slip-labels-for-woocommerce
Auto-generate and attach WooCommerce PDF invoices and packing slips to order emails with customizable templates & bulk print options.
Perfect Brands for WooCommerce
perfect-woocommerce-brands
Perfect Brands for WooCommerce allows you to show product brands in your WooCommerce based store
Kiwiz for WooCommerce Developer Profile
1 plugin · 90 total installs
How We Detect Kiwiz for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/kiwiz-invoices-certification-pdf-file/includes/admin/integration/class.kiwiz-integration-account-settings.php/wp-content/plugins/kiwiz-invoices-certification-pdf-file/includes/class-kiwiz.php/wp-content/plugins/kiwiz-invoices-certification-pdf-file/woocommerce-gateway-certification-de-facture-et-gestion-de-pdf-kiwiz.phpHTML / DOM Fingerprints
kiwiz-noticekiwiz-account-textid="woocommerce_kiwiz_account"