
Propovoice: All-in-One Client Management System Security & Risk Analysis
wordpress.org/plugins/propovoiceAll-in-one client management system for freelancers & agencies on WordPress. Manage leads, deals, invoices & projects. Get paid faster!
Is Propovoice: All-in-One Client Management System Safe to Use in 2026?
Mostly Safe
Score 70/100Propovoice: All-in-One Client Management System is generally safe to use. 3 past CVEs were resolved. Keep it updated.
The PropoInvoice plugin version 1.7.8 exhibits a mixed security posture. While it demonstrates good practices in many areas, such as nearly all SQL queries using prepared statements and a high percentage of properly escaped output, there are significant concerns that warrant attention. The presence of 10 'unserialize' calls is a notable risk, as unserialization of untrusted data can lead to code execution vulnerabilities. Additionally, one unprotected REST API route presents a direct entry point that could be exploited without proper authentication or authorization.
The plugin's vulnerability history is concerning, with three known CVEs, one of which remains unpatched. The types of past vulnerabilities – External Control of File Name or Path, Authorization Bypass, and Cross-Site Scripting – indicate a recurring pattern of exploitable weaknesses. The fact that these vulnerabilities have occurred relatively recently, with the last one in September 2025, suggests ongoing security challenges. Despite a generally robust approach to input validation and capability checks, the combination of legacy issues and new potential attack vectors necessitates a cautious approach.
In conclusion, PropoInvoice v1.7.8 has strengths in its general adherence to secure coding principles for SQL and output handling. However, the critical 'unserialize' function usage, an unprotected REST API endpoint, and a history of serious, unpatched vulnerabilities significantly increase its risk profile. Users should be aware of these risks and prioritize updating to a version that addresses the outstanding vulnerabilities.
Key Concerns
- Unpatched CVE
- Unprotected REST API route
- Dangerous function 'unserialize' used
- High number of past CVEs
Propovoice: All-in-One Client Management System Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Propovoice <= 1.7.6.7 - Unauthenticated Arbitrary File Read
Propovoice CRM <= 1.7.8 - Unauthenticated Insecure Direct Object Reference
Propovoice CRM <= 1.7.6.2 - Unauthenticated Stored Cross-Site Scripting
Propovoice: All-in-One Client Management System Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Propovoice: All-in-One Client Management System Attack Surface
AJAX Handlers 1
REST API Routes 98
WordPress Hooks 43
Scheduled Events 3
Maintenance & Trust
Propovoice: All-in-One Client Management System Maintenance & Trust
Maintenance Signals
Community Trust
Propovoice: All-in-One Client Management System Alternatives
Client Power Tools Portal
client-power-tools
A free, easy-to-use client portal built for designers, developers, consultants, lawyers, and other independent contractors and professionals.
ClientHub
clienthub
Professional client management hub with customizable dashboards, project tracking, and secure customer portal for WordPress.
Projectify Lite
projectify-lite
Projectify Lite is the World’s most advanced project management system which helps you to run your business efficiently and effectively, providing all …
Life Coach Hub
lifecoachhub
Connect your WordPress site to your coaching business. Manage clients, sessions, and courses from your WordPress dashboard.
SWELLEnterprise
swellenterprise
A plugin that connects your website to the SWELLEnterprise services.
Propovoice: All-in-One Client Management System Developer Profile
1 plugin · 1K total installs
How We Detect Propovoice: All-in-One Client Management System
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/propovoice/build/frontend.js/wp-content/plugins/propovoice/build/backend.js/wp-content/plugins/propovoice/build/index.js/wp-content/plugins/propovoice/assets/css/bootstrap.css/wp-content/plugins/propovoice/assets/css/datatable.css/wp-content/plugins/propovoice/assets/css/frontend.css/wp-content/plugins/propovoice/assets/css/styles.css/wp-content/plugins/propovoice/assets/css/select2.min.css+1 more/wp-content/plugins/propovoice/build/frontend.js/wp-content/plugins/propovoice/build/backend.js/wp-content/plugins/propovoice/build/index.jspropovoice/style.css?ver=propovoice/bootstrap.css?ver=propovoice/datatable.css?ver=propovoice/frontend.css?ver=propovoice/styles.css?ver=propovoice/select2.min.css?ver=propovoice/propovoice.style.css?ver=HTML / DOM Fingerprints
ndpv-admin-wrapperndpv-wrapperndpv-client-sectionndpv-deal-sectionndpv-estimate-sectionndpv-invoice-sectionndpv-project-sectionndpv-lead-section+3 more<!-- Created by Propovoice Team --><!-- Propovoice Admin Wrapper --><!-- Propovoice Frontend Wrapper -->data-ndpv-templatedata-ndpv-componentdata-ndpv-routewindow.ndpv_frontend_paramswindow.ndpv_backend_paramsvar ndpv_frontend_params =var ndpv_backend_params =/wp-json/propovoice/v1/clients/wp-json/propovoice/v1/deals/wp-json/propovoice/v1/estimates/wp-json/propovoice/v1/invoices/wp-json/propovoice/v1/projects/wp-json/propovoice/v1/leads/wp-json/propovoice/v1/billing[propovoice_clients][propovoice_deals][propovoice_estimates][propovoice_invoices]