
Yabi einvoice for WooCommerce Security & Risk Analysis
wordpress.org/plugins/wc-yabiThis plugin integrates WordPress with the Yabi electronic invoicing service, allowing the automatic creation and management of DIAN-compliant invoices …
Is Yabi einvoice for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Yabi einvoice for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wc-yabi v4.0.1 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for SQL queries and has no known vulnerabilities in its history, suggesting a generally well-maintained codebase. However, a significant concern arises from its attack surface, with 13 AJAX handlers, 11 of which lack authentication checks. This presents a considerable risk of unauthorized actions being performed if these handlers can be triggered by unauthenticated users.
The static analysis also highlights that a substantial portion of output (54%) is not properly escaped. While there are no critical or high severity taint flows, and no dangerous functions or file operations are used, the lack of proper output escaping on nearly half of all outputs is a potential avenue for Cross-Site Scripting (XSS) vulnerabilities. The presence of only two nonce checks and two capability checks across the entire plugin further exacerbates the risk associated with the unprotected AJAX endpoints.
In conclusion, while the absence of known CVEs and secure SQL practices are strengths, the high number of unprotected AJAX endpoints and significant percentage of unescaped output represent notable security weaknesses that require attention. The plugin's limited use of authentication and nonce checks on its entry points needs to be addressed to improve its overall security.
Key Concerns
- 11 unprotected AJAX handlers
- 54% of outputs unescaped
- Only 2 nonce checks
- Only 2 capability checks
Yabi einvoice for WooCommerce Security Vulnerabilities
Yabi einvoice for WooCommerce Code Analysis
Output Escaping
Data Flow Analysis
Yabi einvoice for WooCommerce Attack Surface
AJAX Handlers 13
WordPress Hooks 12
Maintenance & Trust
Yabi einvoice for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Yabi einvoice for WooCommerce Alternatives
Departamentos y Ciudades de Colombia para Woocommerce
departamentos-y-ciudades-de-colombia-para-woocommerce
WordPress plugin that shows dropdowns for State and City Select for WooCommerce
Indian Rupee Symbol For Woocommerce
indian-rupee-symbol-for-woocommerce
This plugin is used to display new Indian currency rupee symbol for Woocommerce.
Indian Currency Rupee Symbol for Woocommerce
indian-currency-inr-symbol-for-woocommerce
This plugin let you show new INR currency Rupee symbol when using INR currency in WooCommerce.
Indian GST Invoice Suite
indian-gst-invoice-suite
Generate GST Compliant PDF invoices, Supports CGST/SGST/IGST, HSN/SAC, and more for WooCommerce.
MIRATIO – Facturación electrónica Perú
miratio
Ahora puedes emitir comprobantes electrónicos como Boletas y Facturas automáticamente con el plugin de MIRATIO para WooCommerce.
Yabi einvoice for WooCommerce Developer Profile
2 plugins · 30 total installs
How We Detect Yabi einvoice for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wc-yabi/scripts/admin.css/wp-content/plugins/wc-yabi/scripts/admin.js/wp-content/plugins/wc-yabi/scripts/admin.jswc-yabi/scripts/admin.css?ver=wc-yabi/scripts/admin.js?ver=HTML / DOM Fingerprints
yabiAdmin