
Invoice123 Security & Risk Analysis
wordpress.org/plugins/saskaita123-ltManage sales and purchases, clients, inventory, and invoices. Everything business needs is in one system.
Is Invoice123 Safe to Use in 2026?
Generally Safe
Score 99/100Invoice123 has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "saskaita123-lt" v1.6.7 plugin presents a generally positive security posture with several strengths. The absence of known CVEs and the fact that all identified entry points (AJAX handlers) appear to have authentication checks are significant positive indicators. Furthermore, the plugin does not appear to rely on bundled libraries, which can often be a source of outdated and vulnerable code. The code signals analysis reveals a moderate number of SQL queries, with a concerning 20% not using prepared statements, which could lead to SQL injection vulnerabilities if not handled carefully. While there are file operations and external HTTP requests, the lack of taint analysis results and reported vulnerabilities suggests these are likely implemented securely for now. The most significant concern is the lack of capability checks on any of the entry points, meaning that even if authentication is present, any authenticated user could potentially trigger these AJAX actions. This, combined with the less-than-ideal prepared statement usage for SQL queries, suggests a potential for privilege escalation or unauthorized data manipulation, especially if combined with improper output escaping, which is also present at a 45% rate.
Key Concerns
- SQL queries not using prepared statements
- Insufficient output escaping
- No capability checks on entry points
Invoice123 Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Invoice123 <= 1.7.0 - Missing Authorization to Authenticated (Subscriber+) Setting Modification via s123_submit_api_key & s123_submit_invoice_settings AJAX actions
Invoice123 Release Timeline
Invoice123 Code Analysis
SQL Query Safety
Output Escaping
Invoice123 Attack Surface
AJAX Handlers 2
WordPress Hooks 21
Scheduled Events 1
Maintenance & Trust
Invoice123 Maintenance & Trust
Maintenance Signals
Community Trust
Invoice123 Alternatives
Invoice Manager for WooCommerce
wc-invoice-manager
Manage WooCommerce invoices with the first Gutenberg-based editor; it's user-friendly, and ensures professional, accurate billing.
Clielo
clielo
Turn any Custom Post Type into a complete client service platform — chat, orders, payments, invoices and notifications in one plugin.
PDF Invoices & Packing Slips for WooCommerce
woocommerce-pdf-invoices-packing-slips
Create, print & automatically email PDF or XML Invoices & PDF Packing Slips for WooCommerce orders.
Advanced Order Export For WooCommerce
woo-order-export-lite
Export WooCommerce orders to Excel, CSV, XML, JSON, PDF and HTML. Best free order export plugin for WooCommerce.
Order Export & Order Import for WooCommerce
order-import-export-for-woocommerce
The best order export import plugin for WooCommerce. Easily import and export WooCommerce orders and WooCommerce coupons using CSV.
Invoice123 Developer Profile
1 plugin · 400 total installs
How We Detect Invoice123
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/saskaita123-lt/admin/js/s123-invoices-admin.js/wp-content/plugins/saskaita123-lt/admin/js/i123-checkout-inputs.js/wp-content/plugins/saskaita123-lt/admin/js/s123-invoices-admin.js/wp-content/plugins/saskaita123-lt/admin/js/i123-checkout-inputs.jsHTML / DOM Fingerprints
form-row-widename="invoice_type"id="invoice_type"name="_invoice_for_company"id="_invoice_for_company"name="_billing_company_name"id="_billing_company_name"+4 mores123