WooCom CC Invoice Security & Risk Analysis

wordpress.org/plugins/woocom-cc-invoice

Helps user to send CC of the invoice to other third party email.

10 active installs v1.0.0 PHP 5.6+ WP 4.0.0+ Updated Oct 13, 2017
emailinvoiceuserwoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WooCom CC Invoice Safe to Use in 2026?

Generally Safe

Score 85/100

WooCom CC Invoice has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The "woocom-cc-invoice" v1.0.0 plugin exhibits a concerning security posture due to its unprotected entry points. While the plugin demonstrates good practices in its handling of SQL queries, output escaping, and lack of dangerous functions, these strengths are significantly overshadowed by its vulnerabilities. The static analysis reveals two AJAX handlers that lack any authentication checks, presenting a direct path for potential attackers to exploit. The absence of nonce checks and capability checks further exacerbates this risk, as these are fundamental WordPress security mechanisms designed to prevent unauthorized actions.

The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive indicator. However, this does not negate the immediate risks identified in the code analysis. The lack of recorded vulnerabilities might simply be a reflection of its limited exposure or perhaps a lack of in-depth historical security audits rather than an inherent immunity. The absence of taint analysis flows is also noted, but the presence of unprotected AJAX handlers makes this less of a primary concern than the direct exposure.

In conclusion, while "woocom-cc-invoice" v1.0.0 adheres to some secure coding principles, the unprotected AJAX endpoints are a critical weakness that exposes the site to significant risk. The absence of basic security checks on these entry points makes it highly susceptible to various attacks, including Cross-Site Request Forgery (CSRF) and unauthorized data manipulation or execution. Until these entry points are secured with proper authentication and authorization checks, the plugin cannot be considered safe for use.

Key Concerns

  • AJAX handlers without auth checks
  • AJAX handlers without nonce checks
  • AJAX handlers without capability checks
Vulnerabilities
None known

WooCom CC Invoice Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

WooCom CC Invoice Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

WooCom CC Invoice Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
32 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped32 total outputs
Attack Surface
2 unprotected

WooCom CC Invoice Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

noprivwp_ajax_wci_invoice_ccsrc\Initialize\Initialize.php:22
authwp_ajax_wci_invoice_ccsrc\Initialize\Initialize.php:23
WordPress Hooks 9
actionwoocom-cc-invoice_plugin_activatesrc\Admin\Admin.php:17
actionadmin_menusrc\Admin\Admin.php:21
actionadmin_initsrc\Admin\Admin.php:25
actionwp_enqueue_scriptssrc\Assets\AssetsEnqueue.php:27
actionwp_enqueue_scriptssrc\Assets\AssetsEnqueue.php:28
filterwoocommerce_email_classessrc\Email\InitEmail.php:17
filterwoocommerce_thankyousrc\Initialize\Initialize.php:17
filterwoocommerce_order_details_after_order_tablesrc\Initialize\Initialize.php:18
actionplugins_loadedwoocom-cc-invoice.php:88
Maintenance & Trust

WooCom CC Invoice Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedOct 13, 2017
PHP min version5.6
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

WooCom CC Invoice Developer Profile

Rnaby

4 plugins · 30 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WooCom CC Invoice

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woocom-cc-invoice/assets/css/woocom-cc-invoice.css/wp-content/plugins/woocom-cc-invoice/assets/js/woocom-cc-invoice.js
Script Paths
/wp-content/plugins/woocom-cc-invoice/assets/js/woocom-cc-invoice.js
Version Parameters
woocom-cc-invoice/assets/css/woocom-cc-invoice.css?ver=1.0.0woocom-cc-invoice/assets/js/woocom-cc-invoice.js?ver=1.0.0

HTML / DOM Fingerprints

JS Globals
WPAjaxObj
FAQ

Frequently Asked Questions about WooCom CC Invoice