
PDF Forms Filler for WooCommerce Security & Risk Analysis
wordpress.org/plugins/pdf-forms-for-woocommerceAutomatically fill PDF forms with WooCommerce orders and attach generated PDFs to email notifications and order downloads.
Is PDF Forms Filler for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100PDF Forms Filler for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'pdf-forms-for-woocommerce' plugin version 1.1.5 demonstrates a generally good security posture based on the provided static analysis. A significant strength is the complete absence of direct vulnerabilities in its history, with no recorded CVEs. Furthermore, the static analysis reveals a well-protected attack surface, with all identified AJAX handlers properly protected by authentication checks. The code also shows a commendable effort in output escaping, with 79% of outputs being properly handled, and a good number of nonce and capability checks are in place. The lack of any identified taint flows, particularly those with unsanitized paths or critical/high severity, further bolsters its security.
However, there are areas for improvement. The presence of raw SQL queries without the use of prepared statements is a notable concern. While there's only one such query, it represents a potential SQL injection vulnerability if not handled with extreme care by the database layer, especially given the dynamic nature of web applications. Additionally, the plugin bundles the Select2 library, which could introduce risks if the bundled version is outdated or contains known vulnerabilities, although no specific information about its version or history is provided. The file operation count is also relatively high, which warrants scrutiny for potential insecure file handling, though no specific issues were flagged.
In conclusion, this version of the plugin appears to be reasonably secure, with a strong emphasis on access control for its entry points and good output sanitization practices. The absence of historical vulnerabilities is a positive indicator of the developer's commitment to security. The primary area of concern lies in the unescaped SQL query, which should be a priority for remediation. Addressing this and ensuring the security of bundled libraries would significantly enhance its overall security.
Key Concerns
- Raw SQL query without prepared statements
PDF Forms Filler for WooCommerce Security Vulnerabilities
PDF Forms Filler for WooCommerce Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
PDF Forms Filler for WooCommerce Attack Surface
AJAX Handlers 6
WordPress Hooks 23
Maintenance & Trust
PDF Forms Filler for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
PDF Forms Filler for WooCommerce Alternatives
PDF Forms Filler for CF7
pdf-forms-for-contact-form-7
Build Contact Form 7 forms from PDF forms. Get PDFs auto-filled and attached to email messages and/or website responses on form submission.
PDF Forms Filler for WPForms
pdf-forms-for-wpforms
Build WPForms from PDF forms. Get PDFs filled automatically and attached to email messages and/or website responses on form submissions.
Gravity PDF
gravity-forms-pdf-extended
Automatically generate, email and download PDF documents from Gravity Forms entries
Print, PDF, Email by PrintFriendly
printfriendly
The #1 Print, PDF, Email button. Stylish, full featured, customizable. Add custom header, footer, and more.
E2Pdf – Export Pdf Tool for WordPress
e2pdf
PDF Builder for CF7, Divi, Elementor Forms, Everest, Fluent, Formidable, Forminator, Gravity, JFB, Ninja, WPForms, WooCommerce, Post Meta, ACF, etc.
PDF Forms Filler for WooCommerce Developer Profile
5 plugins · 4K total installs
How We Detect PDF Forms Filler for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pdf-forms-for-woocommerce/assets/css/pdf-forms-for-woocommerce.css/wp-content/plugins/pdf-forms-for-woocommerce/assets/js/pdf-forms-for-woocommerce.js/wp-content/plugins/pdf-forms-for-woocommerce/assets/js/pdf-forms-for-woocommerce.jspdf-forms-for-woocommerce/assets/css/pdf-forms-for-woocommerce.css?ver=pdf-forms-for-woocommerce/assets/js/pdf-forms-for-woocommerce.js?ver=HTML / DOM Fingerprints
pdf-forms-for-woocommerce-metaboxdata-pdf-forms-for-woocommerce-order-idpdf_forms_for_woocommerce_vars/wp-json/pdf-forms-for-woocommerce/v1/settings/wp-json/pdf-forms-for-woocommerce/v1/order/meta