
Sliced Invoices – WordPress Invoice Plugin Security & Risk Analysis
wordpress.org/plugins/sliced-invoicesA WordPress invoicing plugin for creating invoices and quotes. Online payments, manage clients, reports, exports, taxes & more.
Is Sliced Invoices – WordPress Invoice Plugin Safe to Use in 2026?
Mostly Safe
Score 74/100Sliced Invoices – WordPress Invoice Plugin is generally safe to use. 4 past CVEs were resolved. Keep it updated.
The Sliced Invoices plugin, version 3.10.0, presents a mixed security posture. While it demonstrates some good practices such as a significant percentage of properly escaped outputs and the use of prepared statements in a majority of its SQL queries, notable concerns exist. The static analysis reveals a substantial attack surface with 9 AJAX handlers, 6 of which lack authentication checks, indicating a potential for unauthorized actions. The taint analysis found several flows with unsanitized paths, though thankfully none reached critical or high severity levels in this version. The plugin's vulnerability history is a significant red flag, with 4 known CVEs and one high-severity, currently unpatched vulnerability. The pattern of past vulnerabilities, including missing authorization, XSS, and SQL injection, further emphasizes the need for vigilance.
Key Concerns
- Unpatched High Severity CVE
- High percentage of AJAX handlers without auth checks
- Taint flows with unsanitized paths
- SQL queries with missing prepared statements
- History of common vulnerability types
Sliced Invoices – WordPress Invoice Plugin Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
Sliced Invoices <= 3.9.5 - Missing Authorization
Sliced Invoices <= 3.9.2 - Missing Authorization
Sliced Invoices <= 3.8.2 - Reflected Cross-Site Scripting
Sliced Invoices < 3.8.4 - Authenticated SQL Injection
Sliced Invoices – WordPress Invoice Plugin Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Sliced Invoices – WordPress Invoice Plugin Attack Surface
AJAX Handlers 9
WordPress Hooks 156
Scheduled Events 2
Maintenance & Trust
Sliced Invoices – WordPress Invoice Plugin Maintenance & Trust
Maintenance Signals
Community Trust
Sliced Invoices – WordPress Invoice Plugin Alternatives
Client Invoicing by Sprout Invoices – Easy Estimates and Invoices for WordPress
sprout-invoices
The best invoicing plugin for WordPress. See how you can get paid faster without those hidden service fees.
Quotes Addon for GetPaid
invoicing-quotes
Quotes add-on for the WordPress payments plugin GetPaid. Allows you to create quotes, send them to clients and convert them to Invoices when accepted …
Easy Invoice – Professional Invoice & Quote Generator
easy-invoice
WordPress invoicing solution for freelancers & businesses. Create invoices, PDF quotes, accept payments, and automate billing—all in one plugin.
WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels
print-invoices-packing-slip-labels-for-woocommerce
Auto-generate and attach WooCommerce PDF invoices and packing slips to order emails with customizable templates & bulk print options.
Print Invoice & Delivery Notes for WooCommerce
woocommerce-delivery-notes
Create and print PDF invoices, delivery notes and receipts for your WooCommerce orders. Choose your document format from multiple templates.
Sliced Invoices – WordPress Invoice Plugin Developer Profile
4 plugins · 5K total installs
How We Detect Sliced Invoices – WordPress Invoice Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sliced-invoices/assets/css/admin-menu.css/wp-content/plugins/sliced-invoices/assets/css/admin-page.css/wp-content/plugins/sliced-invoices/assets/css/editor.css/wp-content/plugins/sliced-invoices/assets/css/frontend.css/wp-content/plugins/sliced-invoices/assets/css/invoices.css/wp-content/plugins/sliced-invoices/assets/css/quotes.css/wp-content/plugins/sliced-invoices/assets/css/shared.css/wp-content/plugins/sliced-invoices/assets/js/admin-menu.js+6 moreSliced Invoicesassets/js/admin-menu.jsassets/js/admin-page.jsassets/js/editor.jsassets/js/frontend.jsassets/js/invoices.jsassets/js/quotes.js+1 moresliced-invoices/assets/css/admin-menu.css?ver=sliced-invoices/assets/css/admin-page.css?ver=sliced-invoices/assets/css/editor.css?ver=sliced-invoices/assets/css/frontend.css?ver=sliced-invoices/assets/css/invoices.css?ver=sliced-invoices/assets/css/quotes.css?ver=sliced-invoices/assets/css/shared.css?ver=sliced-invoices/assets/js/admin-menu.js?ver=sliced-invoices/assets/js/admin-page.js?ver=sliced-invoices/assets/js/editor.js?ver=sliced-invoices/assets/js/frontend.js?ver=sliced-invoices/assets/js/invoices.js?ver=sliced-invoices/assets/js/quotes.js?ver=sliced-invoices/assets/js/shared.js?ver=HTML / DOM Fingerprints
sliced-invoices-admin-menusliced-invoices-admin-pagesliced-invoices-editorsliced-invoices-frontendsliced-invoices-invoicessliced-invoices-quotessliced-invoices-sharedsliced_invoice_template<!-- Sliced Invoices --><!-- Sliced Invoices Database Updates -->data-sliced-invoices-idSlicedAdminMenuSlicedAdminPageSlicedEditorSlicedFrontendSlicedInvoicesSlicedQuotes+1 more/wp-json/sliced-invoices/v1/quotes/wp-json/sliced-invoices/v1/invoices[sliced_invoices][sliced_quotes]