
WebPlanex: GST Invoice India Security & Risk Analysis
wordpress.org/plugins/webplanex-gst-invoice-indiaAutomated Tax Compliance & Streamlined Billing for WooCommerce. Generate GST-compliant invoices effortlessly and stay 100% compliant.
Is WebPlanex: GST Invoice India Safe to Use in 2026?
Generally Safe
Score 100/100WebPlanex: GST Invoice India has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "webplanex-gst-invoice-india" v1.6 exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for SQL queries, handling all file operations safely (none present), and showing a relatively high percentage of properly escaped output. The absence of known vulnerabilities and CVEs in its history is also a strong indicator of a well-maintained and secure plugin over time.
However, significant concerns arise from the static analysis. The plugin exposes two unprotected entry points: one AJAX handler and one REST API route, both lacking authentication or permission checks. This presents a direct attack surface where unauthenticated users could potentially trigger unintended actions or access sensitive information. While the taint analysis shows no critical or high severity unsanitized flows, the single flow with an unsanitized path, coupled with the unprotected entry points, warrants caution. The plugin also makes external HTTP requests, which, without proper validation or sanitization, could be a vector for various attacks.
In conclusion, while the plugin's SQL handling and general output escaping are commendable, the presence of unprotected AJAX and REST API endpoints is a serious security flaw that significantly increases its risk profile. The vulnerability history being clean is a positive, but it doesn't negate the immediate risks identified in the current version's code. Attention should be paid to securing these exposed endpoints.
Key Concerns
- AJAX handler without auth check
- REST API route without permission callback
- Flow with unsanitized path (even if not critical)
- External HTTP requests (potential for misuse)
WebPlanex: GST Invoice India Security Vulnerabilities
WebPlanex: GST Invoice India Code Analysis
Output Escaping
Data Flow Analysis
WebPlanex: GST Invoice India Attack Surface
AJAX Handlers 2
REST API Routes 1
WordPress Hooks 35
Maintenance & Trust
WebPlanex: GST Invoice India Maintenance & Trust
Maintenance Signals
Community Trust
WebPlanex: GST Invoice India Alternatives
Indian GST Invoice Suite
indian-gst-invoice-suite
Generate GST Compliant PDF invoices, Supports CGST/SGST/IGST, HSN/SAC, and more for WooCommerce.
Rename VAT to GST for WooCommerce
rename-vat-to-gst-for-woocommerce
Replaces VAT and Tax terminology with GST throughout WooCommerce (emails, cart, checkout, admin, order pages).
WooCommerce Tax (formerly WooCommerce Shipping & Tax)
woocommerce-services
We’re here to help with tax rates: collect accurate sales tax, automatically.
GST Invoice for WooCommerce
woo-gst
This plugin is for GST tax setting. It set all tax including Tax slabs setting for CGST, SGST and IGST automatically.
Smart GST Calculator
smart-gst-calculator
A simple yet powerful GST calculator for Indian businesses and consumers to calculate Goods and Services Tax (GST) on products/services.
WebPlanex: GST Invoice India Developer Profile
3 plugins · 340 total installs
How We Detect WebPlanex: GST Invoice India
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/webplanex-gst-invoice-india/assets/css/custom-style.csswebplanex-gst-invoice-india/assets/css/custom-style.css?ver=1.6HTML / DOM Fingerprints
webplanex-gst-invoice-india/v1/get_invoice_list