
PDF Invoices & Packing Slips for WooCommerce Security & Risk Analysis
wordpress.org/plugins/woocommerce-pdf-invoices-packing-slipsCreate, print & automatically email PDF or XML Invoices & PDF Packing Slips for WooCommerce orders.
Is PDF Invoices & Packing Slips for WooCommerce Safe to Use in 2026?
Generally Safe
Score 88/100PDF Invoices & Packing Slips for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The plugin "woocommerce-pdf-invoices-packing-slips" v5.8.2 exhibits a generally strong security posture with regard to input handling and access control within its static analysis. A very low percentage of SQL queries utilize prepared statements, and output escaping is nearly universally applied. Nonce and capability checks are present on most entry points, and there are no identified unprotected AJAX handlers or REST API routes. However, the presence of 3 unsanitized path flows in the taint analysis is a significant concern, even though they are not currently classified as critical or high severity. This indicates a potential for path traversal or other file system-related vulnerabilities if these flows are not carefully managed.
The plugin's vulnerability history is a more concerning aspect. With 12 known CVEs, and a history including high and medium severity issues such as Missing Authorization, SSRF, XSS, and SQL Injection, it suggests a recurring pattern of security flaws. While there are no currently unpatched vulnerabilities, the sheer number and types of past issues indicate a need for ongoing vigilance and rigorous security auditing. The last vulnerability recorded in 2026 is likely a typo and should be interpreted within the context of recent historical data, which is not provided. Overall, while the current version shows good development practices for basic security measures, the historical context and identified taint flows warrant caution.
Key Concerns
- Taint flows with unsanitized paths
- High severity historical vulnerabilities
- Medium severity historical vulnerabilities
- Large number of known CVEs
PDF Invoices & Packing Slips for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
13 total CVEs
PDF Invoices & Packing Slips for WooCommerce < 5.9.0 - Authenticated (Shop manager+) PHP Object Injection
PDF Invoices & Packing Slips for WooCommerce <= 5.6.0 - Missing Authorization to Authenticated (Subscriber+) Peppol Identifier Modification
WooCommerce PDF Invoices & Packing Slips <= 4.9.1 - Missing Authorization
WooCommerce PDF Invoices & Packing Slips <= 3.8.6 - Missing Authorization
PDF Invoices & Packing Slips for WooCommerce <= 3.8.0 - Unauthenticated Server-Side Request Forgery
PDF Invoices & Packing Slips for WooCommerce <= 3.8.0 - Unauthenticated Stored Cross-Site Scripting
PDF Invoices & Packing Slips for WooCommerce <= 3.7.6 - Authenticated (Shop Manager+) SQL Injection
WooCommerce PDF Invoices & Packing Slips <= 3.2.5 - Cross Site Request Forgery
WooCommerce PDF Invoices & Packing Slips 2.14.0 - 3.0.0 - Reflected Cross-Site Scripting
WooCommerce PDF Invoices & Packing Slips <= 2.15.0 - Reflected Cross-Site Scripting
WooCommerce PDF Invoices & Packing Slips <= 2.14.5 - Cross-Site Scripting
WooCommerce PDF Invoices & Packing Slips <= 2.10.4 - Reflected Cross-Site Scripting via tab and section parameter
WooCommerce PDF Invoices & Packing Slips <= 2.0.12 - Cross-Site Scripting
PDF Invoices & Packing Slips for WooCommerce Release Timeline
PDF Invoices & Packing Slips for WooCommerce Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
PDF Invoices & Packing Slips for WooCommerce Attack Surface
AJAX Handlers 23
REST API Routes 1
Shortcodes 3
WordPress Hooks 168
Maintenance & Trust
PDF Invoices & Packing Slips for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
PDF Invoices & Packing Slips for WooCommerce Alternatives
WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels
print-invoices-packing-slip-labels-for-woocommerce
Auto-generate and attach WooCommerce PDF invoices and packing slips to order emails with customizable templates & bulk print options.
Invoices for WooCommerce
woocommerce-pdf-invoices
Automatically generate and attach customizable PDF Invoices and PDF Packing Slips for WooCommerce to emails.
WCPDF User Template
bvd-wcpdf-user-template
With this plugin you can change what PDF template will be used for a certain user. "WooCommerce PDF Invoices & Packing Slips" is the plu …
Eledo PDF Attachments for WooCommerce
eledo-pdf-attachments-for-woocommerce
Automatically generate and attach customizable PDF documents to WooCommerce emails by Payment method.
Kitgenix PDF Invoicing for WooCommerce
kitgenix-pdf-invoicing-for-woocommerce
Generate WooCommerce PDF invoices, receipts, packing slips, and credit notes with secure downloads and configurable email attachments.
PDF Invoices & Packing Slips for WooCommerce Developer Profile
7 plugins · 390K total installs
How We Detect PDF Invoices & Packing Slips for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.