
PDF Invoices and Packing Slips for Woocommerce Security & Risk Analysis
wordpress.org/plugins/webplanex-invoicesGenerate PDF Invoices, Shipping Labels, Packing Slips, Delivery Notes and Credit notes for your WooCommerce store.
Is PDF Invoices and Packing Slips for Woocommerce Safe to Use in 2026?
Generally Safe
Score 100/100PDF Invoices and Packing Slips for Woocommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The webplanex-invoices plugin exhibits a mixed security posture. While it demonstrates strong practices in areas like SQL query sanitation and output escaping, significant concerns arise from its attack surface. The presence of one AJAX handler without authentication checks represents a direct entry point for potential malicious activity. This is particularly worrying as it's the only unprotected entry point identified.
The static analysis reveals two taint flows with unsanitized paths, although they are not classified as critical or high severity. This suggests that while no immediate critical vulnerabilities are apparent, there's a potential for data to be processed in an unsafe manner, which could be exploited in conjunction with other weaknesses. The absence of nonce checks on the identified AJAX handler further amplifies this risk, as it allows for potential Cross-Site Request Forgery (CSRF) attacks. The lack of any recorded vulnerability history, while generally positive, might also indicate limited testing or a lack of historical data, rather than guaranteed perfect security.
In conclusion, the plugin has some positive aspects, such as good SQL practices and output escaping. However, the unprotected AJAX handler and the unsanitized taint flows are significant security weaknesses that warrant immediate attention. The absence of nonce checks on the AJAX handler is a critical oversight that needs to be addressed to mitigate potential CSRF vulnerabilities.
Key Concerns
- AJAX handler without auth checks
- Flows with unsanitized paths
- No nonce checks on AJAX
PDF Invoices and Packing Slips for Woocommerce Security Vulnerabilities
PDF Invoices and Packing Slips for Woocommerce Code Analysis
Output Escaping
Data Flow Analysis
PDF Invoices and Packing Slips for Woocommerce Attack Surface
AJAX Handlers 1
WordPress Hooks 24
Maintenance & Trust
PDF Invoices and Packing Slips for Woocommerce Maintenance & Trust
Maintenance Signals
Community Trust
PDF Invoices and Packing Slips for Woocommerce Alternatives
PDF Invoices and Packing Slips For WooCommerce
pdf-invoices-and-packing-slips-for-woocommerce
WooCommerce PDF Invoice plugin helps to generate custom designed invoices for a WooCommerce store. Apart from the Invoice, this plugin can also be use …
Print Invoice & Delivery Notes for WooCommerce
woocommerce-delivery-notes
Create and print PDF invoices, delivery notes and receipts for your WooCommerce orders. Choose your document format from multiple templates.
PDF Invoices & Packing Slips for WooCommerce
woocommerce-pdf-invoices-packing-slips
Create, print & automatically email PDF or XML Invoices & PDF Packing Slips for WooCommerce orders.
WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels
print-invoices-packing-slip-labels-for-woocommerce
Auto-generate and attach WooCommerce PDF invoices and packing slips to order emails with customizable templates & bulk print options.
Invoices for WooCommerce
woocommerce-pdf-invoices
Automatically generate and attach customizable PDF Invoices and PDF Packing Slips for WooCommerce to emails.
PDF Invoices and Packing Slips for Woocommerce Developer Profile
3 plugins · 340 total installs
How We Detect PDF Invoices and Packing Slips for Woocommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/webplanex-invoices/assets/css/custom-style.cssHTML / DOM Fingerprints
webpin_translations/wp-json/webplanex-invoices/v1/settings/wp-json/webplanex-invoices/v1/invoice-data/wp-json/webplanex-invoices/v1/generate-invoice/wp-json/webplanex-invoices/v1/packing-slip-data/wp-json/webplanex-invoices/v1/generate-packing-slip