
WooCom CC Invoice Security & Risk Analysis
wordpress.org/plugins/woocom-cc-invoiceHelps user to send CC of the invoice to other third party email.
Is WooCom CC Invoice Safe to Use in 2026?
Generally Safe
Score 85/100WooCom CC Invoice has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "woocom-cc-invoice" v1.0.0 plugin exhibits a concerning security posture due to its unprotected entry points. While the plugin demonstrates good practices in its handling of SQL queries, output escaping, and lack of dangerous functions, these strengths are significantly overshadowed by its vulnerabilities. The static analysis reveals two AJAX handlers that lack any authentication checks, presenting a direct path for potential attackers to exploit. The absence of nonce checks and capability checks further exacerbates this risk, as these are fundamental WordPress security mechanisms designed to prevent unauthorized actions.
The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive indicator. However, this does not negate the immediate risks identified in the code analysis. The lack of recorded vulnerabilities might simply be a reflection of its limited exposure or perhaps a lack of in-depth historical security audits rather than an inherent immunity. The absence of taint analysis flows is also noted, but the presence of unprotected AJAX handlers makes this less of a primary concern than the direct exposure.
In conclusion, while "woocom-cc-invoice" v1.0.0 adheres to some secure coding principles, the unprotected AJAX endpoints are a critical weakness that exposes the site to significant risk. The absence of basic security checks on these entry points makes it highly susceptible to various attacks, including Cross-Site Request Forgery (CSRF) and unauthorized data manipulation or execution. Until these entry points are secured with proper authentication and authorization checks, the plugin cannot be considered safe for use.
Key Concerns
- AJAX handlers without auth checks
- AJAX handlers without nonce checks
- AJAX handlers without capability checks
WooCom CC Invoice Security Vulnerabilities
WooCom CC Invoice Release Timeline
WooCom CC Invoice Code Analysis
Output Escaping
WooCom CC Invoice Attack Surface
AJAX Handlers 2
WordPress Hooks 9
Maintenance & Trust
WooCom CC Invoice Maintenance & Trust
Maintenance Signals
Community Trust
WooCom CC Invoice Alternatives
Attach Excel Invoice WOOC – WPSHARE247
attach-excel-invoice-wooc-wpshare247
Cho phép tạo file excel có nội dung hóa đơn gửi đính kèm khi gửi email đặt hàng, tải file hóa đơn, zip nhiều file hóa đơn, xuất tất cả các hóa đơn.
VerifyMate Email Verification for WooCommerce
verifymate-email-verification-for-woocommerce
Verify customer emails before login or checkout. Secure WooCommerce registration verification—block fake accounts and spam.
ASPL Email PDF Invoice
aspl-email-pdf-invoice
Using this plugin you can send the invoice PDF automatically with the order confirmation mail sent to the customer.
WCPDF User Template
bvd-wcpdf-user-template
With this plugin you can change what PDF template will be used for a certain user. "WooCommerce PDF Invoices & Packing Slips" is the plu …
Eledo PDF Attachments for WooCommerce
eledo-pdf-attachments-for-woocommerce
Automatically generate and attach customizable PDF documents to WooCommerce emails by Payment method.
WooCom CC Invoice Developer Profile
4 plugins · 30 total installs
How We Detect WooCom CC Invoice
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woocom-cc-invoice/assets/css/woocom-cc-invoice.css/wp-content/plugins/woocom-cc-invoice/assets/js/woocom-cc-invoice.js/wp-content/plugins/woocom-cc-invoice/assets/js/woocom-cc-invoice.jswoocom-cc-invoice/assets/css/woocom-cc-invoice.css?ver=1.0.0woocom-cc-invoice/assets/js/woocom-cc-invoice.js?ver=1.0.0HTML / DOM Fingerprints
WPAjaxObj