
KPiR Security & Risk Analysis
wordpress.org/plugins/kpirEffortless Polish bookkeeping for small businesses—track expenses, manage VAT, and generate JPK reports directly from your WordPress dashboard.
Is KPiR Safe to Use in 2026?
Generally Safe
Score 100/100KPiR has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "kpir" v1.1.3 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for its SQL queries and includes nonce checks for its entry points. There are no recorded vulnerabilities (CVEs) in its history, which is a strong indicator of past security diligence. However, a significant concern arises from the static analysis, which reveals one of its two AJAX handlers lacks authentication checks. Furthermore, the taint analysis identified one flow with an unsanitized path, which, despite not reaching a critical or high severity in this specific analysis, represents a potential avenue for injection attacks if not handled with extreme care. The 53% proper output escaping rate also suggests a notable area for improvement to prevent potential Cross-Site Scripting (XSS) vulnerabilities.
Key Concerns
- AJAX handler without authentication
- Flow with unsanitized path
- Significant portion of output not escaped
KPiR Security Vulnerabilities
KPiR Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
KPiR Attack Surface
AJAX Handlers 2
WordPress Hooks 26
Maintenance & Trust
KPiR Maintenance & Trust
Maintenance Signals
Community Trust
KPiR Alternatives
WooCommerce Tax (formerly WooCommerce Shipping & Tax)
woocommerce-services
We’re here to help with tax rates: collect accurate sales tax, automatically.
One User Avatar | User Profile Picture
one-user-avatar
Use any image from your WordPress Media Library as a custom user avatar or user profile picture. Add your own Default Avatar.
Simple Local Avatars
simple-local-avatars
Adds an avatar upload field to user profiles. Generates requested sizes on demand just like Gravatar!
Gravatar Enhanced – Avatars, Profiles, and Privacy
gravatar-enhanced
The official Gravatar plugin, featuring privacy-focused settings, easy profile updates, and customizable Gravatar Profile blocks.
User Profile Picture
metronet-profile-picture
Set a custom profile image (avatar) for a user using the standard WordPress media upload tool.
KPiR Developer Profile
20 plugins · 89K total installs
How We Detect KPiR
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/kpir/assets/externals/datepicker/css/jquery-ui-datepicker.css/wp-content/plugins/kpir/assets/externals/select2/css/select2.min.css/wp-content/plugins/kpir/assets/styles/kpir-admin.css/wp-content/plugins/kpir/assets/scripts/admin/src/datepicker.js/wp-content/plugins/kpir/assets/scripts/admin/src/invoice.js/wp-content/plugins/kpir/assets/scripts/admin/src/jpk.js/wp-content/plugins/kpir/assets/scripts/admin/src/select2.js/wp-content/plugins/kpir/assets/scripts/admin/kpir.js+1 more/wp-content/plugins/kpir/assets/externals/select2/js/select2.full.min.jskpir-adminadmin-kpirjquery-ui-datepickerselect2HTML / DOM Fingerprints
kpir-dashboard-widget-current-monthkpir-dashboard-widget-past-month<!-- post_types --><!-- admin init --><!-- load github class --><!-- off on not KPiR pages -->+7 more__CLASS__