
WC Recurring Invoice Security & Risk Analysis
wordpress.org/plugins/wc-invoice-pdfWooCommerce invoice PDF generator for recurring / non-recurring orders and Email submission.
Is WC Recurring Invoice Safe to Use in 2026?
Generally Safe
Score 100/100WC Recurring Invoice has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wc-invoice-pdf" v1.7.3 plugin exhibits a concerning security posture due to several critical findings in its static analysis. The presence of 3 AJAX handlers without authentication checks represents a significant attack surface, allowing potentially unauthorized actions. Furthermore, the taint analysis reveals 2 high-severity flows with unsanitized paths, indicating potential vulnerabilities that could be exploited. The plugin also utilizes dangerous functions such as "unserialize" and "exec," which, when combined with unsanitized input, can lead to severe security risks like remote code execution. Despite having no recorded CVEs, the internal code quality issues, particularly the high number of unsanitized taint flows and unprotected AJAX endpoints, overshadow this positive history. The plugin demonstrates some good practices like a high percentage of prepared SQL statements and a reasonable number of output escapes. However, the identified risks in the attack surface and taint analysis, coupled with the use of dangerous functions, necessitate immediate attention and remediation to secure its deployed instances.
Key Concerns
- AJAX handlers without auth checks
- High severity unsanitized taint flows
- Dangerous functions (unserialize, exec)
- Low percentage of properly escaped output
- Bundled outdated library (TCPDF v1.0.004)
WC Recurring Invoice Security Vulnerabilities
WC Recurring Invoice Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
WC Recurring Invoice Attack Surface
AJAX Handlers 3
WordPress Hooks 43
Scheduled Events 1
Maintenance & Trust
WC Recurring Invoice Maintenance & Trust
Maintenance Signals
Community Trust
WC Recurring Invoice Alternatives
Declarando – Invoice Management
declarando-gestion-facturas
Automatically integrate your online store with Declarando to manage invoices, sync orders, and keep your accounting up to date.
TOConline for WooCommerce
toconline-for-woocommerce
TOConline for WooCommerce is a WordPress plugin that automates invoicing with TOConline.
PDF InvoiceX – PDF Invoice for WooCommerce
pdf-invoicex
Generate and download PDF invoices for WooCommerce orders, with customizable settings, email attachments, and bulk generation.
Qinvoice Connect for Woocommerce
qinvoice-connect-for-woocommerce
Connects your Woocommerce installation to q-invoice for automatic invoicing.
All In One For Woocommerce
all-in-one-wc
Enhance your WooCommerce store with custom button labels, PDF invoicing, advanced shipping options, and much more.
WC Recurring Invoice Developer Profile
3 plugins · 50 total installs
How We Detect WC Recurring Invoice
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wc-invoice-pdf/browser/js/wc-recurring-admin.js/wp-content/plugins/wc-invoice-pdf/browser/style/wc-recurring.cssbrowser/js/wc-recurring-admin.jswc-invoice-pdf/browser/js/wc-recurring-admin.js?ver=wc-invoice-pdf/browser/style/wc-recurring.css?ver=