Számlahegy WooCommerce Security & Risk Analysis

wordpress.org/plugins/szamlahegy-woocommerce

A Számlahegy online számlázó program plugin-je Wordpress Woocommerce webáruházhoz.

10 active installs v1.2.8 PHP + WP 4.5+ Updated Jan 16, 2018
szamlazasszamlaszamlahegywoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Számlahegy WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Számlahegy WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The "szamlahegy-woocommerce" plugin v1.2.8 presents a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for SQL queries, having no recorded vulnerabilities (CVEs), and performing capability checks. The absence of dangerous functions, file operations, and bundled libraries also contributes to a generally cleaner codebase. However, significant concerns arise from the static analysis. The plugin has a single entry point via an unprotected AJAX handler, which is a critical security weakness. While taint analysis did not identify critical or high severity unsanitized paths, the presence of one flow with an unsanitized path, even if of lower severity, coupled with the unprotected AJAX endpoint, creates a potential attack vector. The low percentage of properly escaped output (8%) further exacerbates this risk, as it increases the likelihood of cross-site scripting (XSS) vulnerabilities, particularly within the unprotected AJAX handler.

The lack of any historical vulnerabilities might indicate a mature and well-maintained plugin, or simply a lack of historical auditing. Regardless, the current static analysis reveals a specific, immediate risk in the unprotected AJAX handler. The overall security is compromised by this single, exposed entry point and the insufficient output escaping, despite strengths in data handling and a clean vulnerability history. Addressing the unprotected AJAX handler and improving output sanitization are paramount to mitigating the identified risks.

Key Concerns

  • Unprotected AJAX handler
  • Low percentage of properly escaped output
  • Flows with unsanitized paths
Vulnerabilities
None known

Számlahegy WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Számlahegy WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
11
1 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

8% escaped12 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<szamlahegy-woocommerce-admin-management> (admin\partials\szamlahegy-woocommerce-admin-management.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Számlahegy WooCommerce Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_szamlahegy_wc_create_invoiceincludes\class-szamlahegy-woocommerce.php:161
WordPress Hooks 8
actionplugins_loadedincludes\class-szamlahegy-woocommerce.php:141
actionadmin_enqueue_scriptsincludes\class-szamlahegy-woocommerce.php:156
actionadmin_enqueue_scriptsincludes\class-szamlahegy-woocommerce.php:157
filterwoocommerce_general_settingsincludes\class-szamlahegy-woocommerce.php:159
actionadd_meta_boxesincludes\class-szamlahegy-woocommerce.php:160
actionwp_enqueue_scriptsincludes\class-szamlahegy-woocommerce.php:177
actionwp_enqueue_scriptsincludes\class-szamlahegy-woocommerce.php:178
actionwoocommerce_order_status_completedincludes\class-szamlahegy-woocommerce.php:179
Maintenance & Trust

Számlahegy WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedJan 16, 2018
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Számlahegy WooCommerce Developer Profile

szamlahegy

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Számlahegy WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/szamlahegy-woocommerce/css/szamlahegy-woocommerce-admin.css/wp-content/plugins/szamlahegy-woocommerce/js/szamlahegy-woocommerce-admin.js
Script Paths
/wp-content/plugins/szamlahegy-woocommerce/js/szamlahegy-woocommerce-admin.js
Version Parameters
szamlahegy-woocommerce/css/szamlahegy-woocommerce-admin.css?ver=szamlahegy-woocommerce/js/szamlahegy-woocommerce-admin.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- Számlahegy.hu beállítások --><!-- Teszt üzemmód --><!-- Alapértelmezett termékazonosító vagy SZJ szám --><!-- Számlahegy szerver URL -->+1 more
Data Attributes
id="szamlahegy_order_option"class="chosen_select"
JS Globals
szamlahegy_wc_params
FAQ

Frequently Asked Questions about Számlahegy WooCommerce