
PDF Ink Lite – PDF Watermark & Password Protection Security & Risk Analysis
wordpress.org/plugins/waterwoo-pdfThe original WordPress PDF Watermark & password plugin (fka WaterWoo) Automatically 'tattoo' & protect PDFs for WooCommerce, EDD, an …
Is PDF Ink Lite – PDF Watermark & Password Protection Safe to Use in 2026?
Generally Safe
Score 100/100PDF Ink Lite – PDF Watermark & Password Protection has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "waterwoo-pdf" v4.0.11 plugin exhibits a generally good security posture, with no publicly known vulnerabilities and a significant portion of its outputs being properly escaped. The static analysis also indicates a small attack surface with no immediately obvious unprotected entry points like AJAX handlers, REST API routes, or shortcodes accessible without authentication. However, there are some areas of concern that warrant attention. The presence of two instances of the `unserialize` function is a significant risk, as deserialization vulnerabilities can be critical if user-controlled data is passed to it without proper validation and sanitization. Additionally, the plugin executes raw SQL queries without using prepared statements, which introduces a risk of SQL injection if any dynamic data is incorporated into these queries without thorough sanitization. The plugin does bundle the TCPDF library, which is an older version (v1.0.004), and while no vulnerabilities are listed for this specific version, outdated bundled libraries can be a potential attack vector. Despite these risks, the absence of reported CVEs and the relatively low number of identified code signals suggest a developing security awareness within the plugin. The plugin's strengths lie in its limited attack surface and strong output escaping, but the identified risks related to `unserialize`, raw SQL, and bundled libraries need to be addressed to improve its overall security.
Key Concerns
- Dangerous function 'unserialize' detected
- SQL queries not using prepared statements
- Bundled library TCPDF v1.0.004 is outdated
PDF Ink Lite – PDF Watermark & Password Protection Security Vulnerabilities
PDF Ink Lite – PDF Watermark & Password Protection Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
PDF Ink Lite – PDF Watermark & Password Protection Attack Surface
WordPress Hooks 45
Maintenance & Trust
PDF Ink Lite – PDF Watermark & Password Protection Maintenance & Trust
Maintenance Signals
Community Trust
PDF Ink Lite – PDF Watermark & Password Protection Alternatives
WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels
print-invoices-packing-slip-labels-for-woocommerce
Auto-generate and attach WooCommerce PDF invoices and packing slips to order emails with customizable templates & bulk print options.
Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools
woocommerce-jetpack
Supercharge WooCommerce with FREE Abandoned Cart Recovery, Product Variation Swatches, PDF Invoices & 100+ tools. Boost sales & save time.
Print, PDF, Email by PrintFriendly
printfriendly
The #1 Print, PDF, Email button. Stylish, full featured, customizable. Add custom header, footer, and more.
Easy Media Download
easy-media-download
Easy Media Download allows you to embed download buttons on your WordPress site. Add file download functionality with this WordPress download plugin.
Bulk Edit Posts and Products in Spreadsheet
wp-sheet-editor-bulk-spreadsheet-editor-for-posts-and-pages
Modern Bulk Editor for Posts and Pages, create and edit hundreds of posts at once in a spreadsheet inside wp-admin. Search and quick edits.
PDF Ink Lite – PDF Watermark & Password Protection Developer Profile
1 plugin · 2K total installs
How We Detect PDF Ink Lite – PDF Watermark & Password Protection
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/waterwoo-pdf/assets/css/pdf-styles.css/wp-content/plugins/waterwoo-pdf/assets/js/pdf-scripts.js/wp-content/plugins/waterwoo-pdf/assets/js/pdf-scripts.jswaterwoo-pdf/assets/css/pdf-styles.css?ver=waterwoo-pdf/assets/js/pdf-scripts.js?ver=HTML / DOM Fingerprints
pdfink-upgradepdfink-upgrade-tbdata-wwpdf-settingswindow.wwpdf_settings