Invoice123 Security & Risk Analysis

wordpress.org/plugins/saskaita123-lt

Manage sales and purchases, clients, inventory, and invoices. Everything business needs is in one system.

400 active installs v1.6.8 PHP 7.2+ WP 5.5+ Updated Mar 26, 2026
invoicesorders
99
A · Safe
CVEs total1
Unpatched0
Last CVEJul 9, 2026
Safety Verdict

Is Invoice123 Safe to Use in 2026?

Generally Safe

Score 99/100

Invoice123 has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Jul 9, 2026Updated 3mo ago
Risk Assessment

The "saskaita123-lt" v1.6.7 plugin presents a generally positive security posture with several strengths. The absence of known CVEs and the fact that all identified entry points (AJAX handlers) appear to have authentication checks are significant positive indicators. Furthermore, the plugin does not appear to rely on bundled libraries, which can often be a source of outdated and vulnerable code. The code signals analysis reveals a moderate number of SQL queries, with a concerning 20% not using prepared statements, which could lead to SQL injection vulnerabilities if not handled carefully. While there are file operations and external HTTP requests, the lack of taint analysis results and reported vulnerabilities suggests these are likely implemented securely for now. The most significant concern is the lack of capability checks on any of the entry points, meaning that even if authentication is present, any authenticated user could potentially trigger these AJAX actions. This, combined with the less-than-ideal prepared statement usage for SQL queries, suggests a potential for privilege escalation or unauthorized data manipulation, especially if combined with improper output escaping, which is also present at a 45% rate.

Key Concerns

  • SQL queries not using prepared statements
  • Insufficient output escaping
  • No capability checks on entry points
Vulnerabilities
1 published

Invoice123 Security Vulnerabilities

CVEs by Year

1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2026-9857medium · 4.3Missing Authorization

Invoice123 <= 1.7.0 - Missing Authorization to Authenticated (Subscriber+) Setting Modification via s123_submit_api_key & s123_submit_invoice_settings AJAX actions

Jul 9, 2026 Patched in 1.7.1 (1d)
Version History

Invoice123 Release Timeline

v1.6.8Current1 CVE
v1.6.71 CVE
v1.6.61 CVE
v1.6.51 CVE
v1.6.41 CVE
v1.6.31 CVE
v1.6.21 CVE
v1.6.11 CVE
v1.6.01 CVE
v1.5.101 CVE
v1.5.91 CVE
v1.5.81 CVE
v1.5.71 CVE
v1.5.61 CVE
v1.5.51 CVE
v1.5.41 CVE
v1.5.31 CVE
v1.5.21 CVE
v1.5.11 CVE
v1.4.131 CVE
Code Analysis
Analyzed Mar 16, 2026

Invoice123 Code Analysis

Dangerous Functions
0
Raw SQL Queries
8
2 prepared
Unescaped Output
29
36 escaped
Nonce Checks
2
Capability Checks
0
File Operations
4
External Requests
3
Bundled Libraries
0

SQL Query Safety

20% prepared10 total queries

Output Escaping

55% escaped65 total outputs
Attack Surface

Invoice123 Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_s123_submit_api_keyincludes\pages\S123_ApiKey.php:21
authwp_ajax_s123_submit_invoice_settingsincludes\pages\S123_InvoiceSettings.php:18
WordPress Hooks 21
actionadmin_enqueue_scriptsincludes\base\S123_Enqueue.php:17
actionwp_enqueue_scriptsincludes\base\S123_Enqueue.php:18
actioninitincludes\base\S123_I18n.php:15
filterwoocommerce_checkout_fieldsincludes\pages\S123_Checkout.php:24
actionwoocommerce_checkout_create_orderincludes\pages\S123_Checkout.php:25
actionwoocommerce_admin_order_data_after_billing_addressincludes\pages\S123_Checkout.php:26
actionwoocommerce_process_shop_order_metaincludes\pages\S123_Checkout.php:27
actionwoocommerce_initincludes\pages\S123_Checkout.php:28
actionwoocommerce_sanitize_additional_fieldincludes\pages\S123_Checkout.php:29
actionadmin_menuincludes\pages\S123_Settings.php:36
actionadmin_initincludes\pages\S123_Settings.php:38
actionwoocommerce_email_sentincludes\woocommerce\I123_OrderEmail.php:30
actionwoocommerce_email_attachmentsincludes\woocommerce\I123_OrderEmail.php:31
actionwoocommerce_order_actionsincludes\woocommerce\I123_OrderEmail.php:32
actionwoocommerce_order_action_send_i123_invoiceincludes\woocommerce\I123_OrderEmail.php:33
filterwoocommerce_email_classesincludes\woocommerce\I123_OrderEmail.php:34
filtercron_schedulesincludes\woocommerce\I123_Warehouse.php:28
actioni123_sync_warehouse_cron_hookincludes\woocommerce\I123_Warehouse.php:30
actionwoocommerce_order_status_changedincludes\woocommerce\S123_Product.php:41
actionwoocommerce_checkout_order_processedincludes\woocommerce\S123_Product.php:42
actioninvoice123_payment_successincludes\woocommerce\S123_Product.php:43

Scheduled Events 1

i123_sync_warehouse_cron_hook
Maintenance & Trust

Invoice123 Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 26, 2026
PHP min version7.2
Downloads13K

Community Trust

Rating0/100
Number of ratings0
Active installs400
Developer Profile

Invoice123 Developer Profile

Invoice123

1 plugin · 400 total installs

99
trust score
Avg Security Score
99/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect Invoice123

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/saskaita123-lt/admin/js/s123-invoices-admin.js/wp-content/plugins/saskaita123-lt/admin/js/i123-checkout-inputs.js
Script Paths
/wp-content/plugins/saskaita123-lt/admin/js/s123-invoices-admin.js/wp-content/plugins/saskaita123-lt/admin/js/i123-checkout-inputs.js

HTML / DOM Fingerprints

CSS Classes
form-row-wide
Data Attributes
name="invoice_type"id="invoice_type"name="_invoice_for_company"id="_invoice_for_company"name="_billing_company_name"id="_billing_company_name"+4 more
JS Globals
s123
FAQ

Frequently Asked Questions about Invoice123