
PeproDev WooCommerce Receipt Uploader Security & Risk Analysis
wordpress.org/plugins/pepro-bacs-receipt-upload-for-woocommerceUpload Receipt for Any Payment method in WooCommerce
Is PeproDev WooCommerce Receipt Uploader Safe to Use in 2026?
Generally Safe
Score 91/100PeproDev WooCommerce Receipt Uploader has a strong security track record. Known vulnerabilities have been patched promptly.
The pepro-bacs-receipt-upload-for- WooCommerce plugin, version 2.8.0, exhibits a generally good security posture with several positive indicators. The absence of unprotected AJAX handlers, REST API routes, and a complete lack of raw SQL queries or external HTTP requests are commendable. Nonce and capability checks are present, suggesting an effort to implement basic WordPress security measures. However, a notable concern lies in the output escaping, where 55% of outputs are not properly escaped, indicating a potential for Cross-Site Scripting (XSS) vulnerabilities. The taint analysis also revealed one flow with an unsanitized path, which, while not classified as critical or high severity, warrants attention.
The vulnerability history shows one past medium severity CVE, which was a Cross-Site Scripting vulnerability, further underscoring the risk associated with improper input handling and output escaping. The fact that this vulnerability is currently unpatched is a significant weakness. While the current static analysis did not flag any new critical or high severity issues, the lingering presence of unpatched vulnerabilities and the identified output escaping and taint flow concerns suggest that the plugin may still be susceptible to exploitation.
In conclusion, the plugin demonstrates adherence to some security best practices but has clear areas of concern regarding output escaping and a history of unpatched vulnerabilities. While the static analysis did not reveal immediate critical flaws, the combination of past vulnerabilities and current code signals necessitates caution. The development team should prioritize addressing the output escaping issues and ensuring all past vulnerabilities are thoroughly patched.
Key Concerns
- 55% of outputs not properly escaped
- 1 flow with unsanitized paths
- 1 medium unpatched CVE
PeproDev WooCommerce Receipt Uploader Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
PeproDev WooCommerce Receipt Uploader <= 2.6.9 - Reflected Cross-Site Scripting
PeproDev WooCommerce Receipt Uploader Code Analysis
Output Escaping
Data Flow Analysis
PeproDev WooCommerce Receipt Uploader Attack Surface
AJAX Handlers 2
Shortcodes 2
WordPress Hooks 34
Maintenance & Trust
PeproDev WooCommerce Receipt Uploader Maintenance & Trust
Maintenance Signals
Community Trust
PeproDev WooCommerce Receipt Uploader Alternatives
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Google for WooCommerce
google-listings-and-ads
Native integration with Google that allows merchants to easily display their products across Google’s network.
WooPayments: Integrated WooCommerce Payments
woocommerce-payments
Securely accept credit and debit cards on your WooCommerce store. Manage payments without leaving your WordPress dashboard. Only with WooPayments.
WooCommerce PayPal Payments
woocommerce-paypal-payments
PayPal's latest payment processing solution. Accept PayPal, Pay Later, credit/debit cards, alternative digital wallets and bank accounts.
Click to Chat – HoliThemes
click-to-chat-for-whatsapp
WhatsApp Chat🔥. Let's make your Web page visitors contact you through 'WhatsApp', 'WhatsApp Business'. Add matching Widget✅
PeproDev WooCommerce Receipt Uploader Developer Profile
6 plugins · 8K total installs
How We Detect PeproDev WooCommerce Receipt Uploader
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pepro-bacs-receipt-upload-for-woocommerce/assets/backend/images/NoImageLarge.png/wp-content/plugins/pepro-bacs-receipt-upload-for-woocommerce/assets/frontend/css/style.css/wp-content/plugins/pepro-bacs-receipt-upload-for-woocommerce/assets/frontend/js/upload.js/wp-content/plugins/pepro-bacs-receipt-upload-for-woocommerce/assets/frontend/js/upload.jspepro-bacs-receipt-upload-for-woocommerce/assets/frontend/css/style.css?ver=pepro-bacs-receipt-upload-for-woocommerce/assets/frontend/js/upload.js?ver=HTML / DOM Fingerprints
peprodev-receipt-uploader<!-- PeproDev WooCommerce Receipt Uploader :: Developed by Pepro Dev. Group (https://pepro.dev/) -->data-wc-upload-receipt-nonce=data-order-id=data-product-id=data-max-file-size=peprodev_receipt_uploader_ajax_object[receipt-form][receipt-preview]