
Wicked Invoicing Security & Risk Analysis
wordpress.org/plugins/wicked-invoicingSimple, friendly invoicing for WordPress. Create and send invoices to your clients directly from your dashboard.
Is Wicked Invoicing Safe to Use in 2026?
Generally Safe
Score 100/100Wicked Invoicing has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wicked-invoicing" v1.1.3 plugin exhibits a generally strong security posture with excellent adherence to secure coding practices. The static analysis shows a complete absence of dangerous functions, all SQL queries are properly prepared, and output is consistently escaped, which significantly mitigates risks of code injection and cross-site scripting. The lack of external HTTP requests and bundled libraries further reduces its attack surface. However, a notable concern is the presence of two unprotected REST API routes, which represent direct entry points into the plugin's functionality that could be exploited if not properly secured at the application level or via WordPress's own authorization mechanisms. The plugin's vulnerability history is clear, with zero recorded CVEs, suggesting a commitment to security and a lack of previously identified critical flaws. This indicates a well-maintained codebase, but the unprotected REST API routes are a specific area of focus for potential exploitation.
Key Concerns
- Unprotected REST API routes found
Wicked Invoicing Security Vulnerabilities
Wicked Invoicing Release Timeline
Wicked Invoicing Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Wicked Invoicing Attack Surface
REST API Routes 2
WordPress Hooks 59
Maintenance & Trust
Wicked Invoicing Maintenance & Trust
Maintenance Signals
Community Trust
Wicked Invoicing Alternatives
Invoct – PDF Invoices & Billing for WooCommerce
kirilkirkov-pdf-invoice-manager
Professional PDF invoicing & billing for WooCommerce and WordPress, with Stripe payments and automated VAT/tax handling.
WeoInvoice
weoinvoice
Automatically generate invoices for WooCommerce orders using the WeoInvoice platform.
Client Invoicing by Sprout Invoices – Easy Estimates and Invoices for WordPress
sprout-invoices
The best invoicing plugin for WordPress. See how you can get paid faster without those hidden service fees.
WP Forms + Sprout Invoices – Easy Invoice & Quote Submissions
sprout-invoices-wp-forms
Dynamic invoicing (and estimates/quotes) from WP Form submissions.
Declarando – Invoice Management
declarando-gestion-facturas
Automatically integrate your online store with Declarando to manage invoices, sync orders, and keep your accounting up to date.
Wicked Invoicing Developer Profile
1 plugin · 0 total installs
How We Detect Wicked Invoicing
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wicked-invoicing/build/admin.css/wp-content/plugins/wicked-invoicing/build/admin.js/wp-content/plugins/wicked-invoicing/build/frontend.css/wp-content/plugins/wicked-invoicing/build/frontend.js/wp-content/plugins/wicked-invoicing/build/invoice-builder.css/wp-content/plugins/wicked-invoicing/build/invoice-builder.js/wp-content/plugins/wicked-invoicing/build/invoice-editor.css/wp-content/plugins/wicked-invoicing/build/invoice-editor.js+17 more/wp-content/plugins/wicked-invoicing/build/admin.js/wp-content/plugins/wicked-invoicing/build/frontend.js/wp-content/plugins/wicked-invoicing/build/invoice-builder.js/wp-content/plugins/wicked-invoicing/build/invoice-editor.js/wp-content/plugins/wicked-invoicing/build/invoice-preview.js/wp-content/plugins/wicked-invoicing/build/settings.js+7 morewicked-invoicing/build/admin.css?ver=wicked-invoicing/build/admin.js?ver=wicked-invoicing/build/frontend.css?ver=wicked-invoicing/build/frontend.js?ver=wicked-invoicing/build/invoice-builder.css?ver=wicked-invoicing/build/invoice-builder.js?ver=wicked-invoicing/build/invoice-editor.css?ver=wicked-invoicing/build/invoice-editor.js?ver=wicked-invoicing/build/invoice-preview.css?ver=wicked-invoicing/build/invoice-preview.js?ver=wicked-invoicing/build/settings.css?ver=wicked-invoicing/build/settings.js?ver=wicked-invoicing/assets/css/admin.css?ver=wicked-invoicing/assets/css/frontend.css?ver=wicked-invoicing/assets/css/invoice-builder.css?ver=wicked-invoicing/assets/css/invoice-editor.css?ver=wicked-invoicing/assets/css/invoice-preview.css?ver=wicked-invoicing/assets/css/settings.css?ver=wicked-invoicing/assets/js/admin.js?ver=wicked-invoicing/assets/js/frontend.js?ver=wicked-invoicing/assets/js/invoice-builder.js?ver=wicked-invoicing/assets/js/invoice-editor.js?ver=wicked-invoicing/assets/js/invoice-preview.js?ver=wicked-invoicing/assets/js/settings.js?ver=wicked-invoicing/assets/js/vendor/marked.min.js?ver=HTML / DOM Fingerprints
wicked-invoicing-adminwicked-invoice-form-containerwicked-invoice-form-wrapperwicked-invoice-form-contentwicked-add-new-invoice-formwicked-invoice-billing-address-blockwicked-invoice-shipping-address-blockwicked-invoice-line-item-table+2 more<!-- Wicked Invoicing Frontend Template --><!-- Wicked Invoicing Invoice Preview --><!-- Wicked Invoicing Settings Form --><!-- Wicked Invoice Line Item Row -->+1 moredata-wicked-invoice-iddata-wicked-invoice-statedata-wicked-client-iddata-wicked-invoice-template-iddata-wicked-payment-gatewaydata-wicked-line-item-id+2 morewickedInvoicingAdminwickedInvoicingFrontendwickedInvoiceBuilderwickedInvoiceEditorwickedInvoicePreviewwickedSettings/wp-json/wicked-invoicing/v1/invoices/wp-json/wicked-invoicing/v1/clients/wp-json/wicked-invoicing/v1/settings/wp-json/wicked-invoicing/v1/payments/wp-json/wicked-invoicing/v1/templates/wp-json/wicked-invoicing/v1/line-items/wp-json/wicked-invoicing/v1/admin-bar[wicked_invoices][wicked_invoice_form][wicked_invoice_preview][wicked_client_list]