
PDF Creator Lite Security & Risk Analysis
wordpress.org/plugins/pdf-creator-liteLet visitors and admins create PDFs of your site content at the click of a button.
Is PDF Creator Lite Safe to Use in 2026?
Use With Caution
Score 63/100PDF Creator Lite has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The pdf-creator-lite plugin v1.2 exhibits a mixed security posture, with some encouraging signs but significant areas of concern. While the plugin demonstrates good practices by exclusively using prepared statements for SQL queries and performing a substantial amount of output escaping (74%), it falters critically in input validation and authentication for its entry points. The presence of three unprotected AJAX handlers presents a substantial attack surface, making the plugin vulnerable to unauthorized actions if exploited. Furthermore, the taint analysis revealing five flows with unsanitized paths, although not flagged as critical or high severity, indicates potential vulnerabilities in how user-supplied data is handled, especially in conjunction with file operations. The vulnerability history, specifically the single medium severity CVE attributed to Cross-Site Request Forgery (CSRF) and its recency (2025-10-29), further underscores the importance of robust authentication and authorization mechanisms. The lack of nonce checks on AJAX handlers directly contributes to this CSRF risk. The bundled TCPDF library, while not explicitly stated as outdated or vulnerable in this data, is a common vector for vulnerabilities, and its version should be verified against known security advisories.
Key Concerns
- Unprotected AJAX handlers
- Unsanitized paths in taint flows
- Unpatched CVE (medium severity)
- Lack of nonce checks on AJAX
- Bundled outdated library (TCPDF v1.0.004)
- Output escaping below 90%
PDF Creator Lite Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
PDF Creator Lite <= 1.2 - Cross-Site Request Forgery
PDF Creator Lite Release Timeline
PDF Creator Lite Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
PDF Creator Lite Attack Surface
AJAX Handlers 3
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
PDF Creator Lite Maintenance & Trust
Maintenance Signals
Community Trust
PDF Creator Lite Alternatives
PDF Embedder
pdf-embedder
Seamlessly embed PDFs into your content, with customizations and intelligent responsive resizing, and no third-party services or iframes.
PDF Invoices & Packing Slips for WooCommerce
woocommerce-pdf-invoices-packing-slips
Create, print & automatically email PDF or XML Invoices & PDF Packing Slips for WooCommerce orders.
DearFlip – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer
3d-flipbook-dflip-lite
DearFlip creates a PDF Flipbook, 3D Flipbook, PDF viewer, PDF embed for WordPress sites. Create impressive and realistic 3D flipbooks with PDFs.
EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents
embedpress
EmbedPress lets you embed videos, pages, social feeds, embed PDF 3D flipbooks & other content on WordPress without coding & enhance storytelling.
3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery
interactive-3d-flipbook-powered-physics-engine
3D FlipBook is PDF Viewer, allowing to browse images, PDFs or HTMLs as flipbook. Flipbook attracts user attention and makes more impression on him.
PDF Creator Lite Developer Profile
2 plugins · 40 total installs
How We Detect PDF Creator Lite
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pdf-creator-lite/js/admin.js/wp-content/plugins/pdf-creator-lite/colourpicker/spectrum.css/wp-content/plugins/pdf-creator-lite/js/frontend.js/wp-content/plugins/pdf-creator-lite/js/admin.js/wp-content/plugins/pdf-creator-lite/js/frontend.jsHTML / DOM Fingerprints
id="forceDownloadLink"id="previewLink"id="previewFrame"id="forceDownload"id="forceDownloadFrame"ssapdfAjaxSSAPDF