
FacturaONE para WooCommerce con VeriFactu Security & Risk Analysis
wordpress.org/plugins/wp-facturaoneConecta tu WooCommerce con el ERP FacturaONE ERP y gestiona ventas, stock y facturas en tiempo real. Compatible con VeriFactu 2026 y TicketBAI.
Is FacturaONE para WooCommerce con VeriFactu Safe to Use in 2026?
Generally Safe
Score 100/100FacturaONE para WooCommerce con VeriFactu has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-facturaone plugin v5.03 exhibits a concerning security posture, primarily due to a significant number of unprotected entry points. With 4 out of 5 identified entry points lacking authentication or permission checks, the plugin is highly susceptible to unauthorized access and potential exploitation. The taint analysis further reinforces these concerns, revealing 2 critical high-severity flows with unsanitized paths. While the plugin demonstrates some good practices like a reasonable percentage of prepared SQL statements and nonce checks, these are overshadowed by the critical security gaps in its input handling and access control mechanisms.
The plugin's vulnerability history is currently clean, with no recorded CVEs. This could indicate a lack of targeted attacks or a recent focus on security by the developers. However, the presence of critical taint flows and numerous unprotected entry points in the code analysis suggests that the plugin is inherently vulnerable to common attack vectors. The absence of past vulnerabilities should not be interpreted as a guarantee of future security, especially given the identified code-level weaknesses.
In conclusion, while the plugin shows promise in areas like SQL query preparation and output escaping, its security is severely compromised by the large attack surface of unprotected AJAX handlers and REST API routes, coupled with critical taint flows. Urgent attention is required to address these vulnerabilities to prevent potential security incidents.
Key Concerns
- Unprotected AJAX handlers
- Unprotected REST API routes
- High severity taint flows
- Bundled outdated library (jQuery v1.7.1)
FacturaONE para WooCommerce con VeriFactu Security Vulnerabilities
FacturaONE para WooCommerce con VeriFactu Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
FacturaONE para WooCommerce con VeriFactu Attack Surface
AJAX Handlers 4
REST API Routes 1
WordPress Hooks 95
Maintenance & Trust
FacturaONE para WooCommerce con VeriFactu Maintenance & Trust
Maintenance Signals
Community Trust
FacturaONE para WooCommerce con VeriFactu Alternatives
Contabilium Oficial para WooCommerce
contabilium-oficial-para-woo
Contabilium es un sistema de gestión online que te permite administrar todos tus ingresos y gastos de una forma sencilla y rápida en cualquier momento …
TicketBAI Facturas para WooCommerce
wp-ticketbai
Emite Facturas desde tu WooCommerce a TicketBAI con el código QR desde WordPress, gestiona fácilmente Anulaciones, Rectificatvas, Facturas PDF.
Afterpay Gateway for WooCommerce
afterpay-gateway-for-woocommerce
Provide Afterpay as a payment option for WooCommerce orders.
Holded integration
holded-integration
Holded service integration with WooCommerce
Quaderno: Global Tax & Invoicing Automation for WooCommerce
woocommerce-quaderno
Automate global tax calculations and compliant invoicing for WooCommerce. Handle sales tax, VAT, GST worldwide with instant reports.
FacturaONE para WooCommerce con VeriFactu Developer Profile
2 plugins · 100 total installs
How We Detect FacturaONE para WooCommerce con VeriFactu
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-facturaone/assets/FONE_main.cssHTML / DOM Fingerprints
data-fone-product-iddata-fone-client-idFacturaONE_AJAX_URLFacturaONE_NONCEFacturaONE_ADD_TO_CART_URLFacturaONE_REMOVE_FROM_CART_URLFacturaONE_UPDATE_QUANTITY_URLFacturaONE_GET_CART_CONTENTS_URL+7 more/wp-json/facturaone/v1/order_status/wp-json/facturaone/v1/update_cart_item/wp-json/facturaone/v1/get_payment_methods/wp-json/facturaone/v1/add_to_cart/wp-json/facturaone/v1/remove_from_cart/wp-json/facturaone/v1/update_quantity/wp-json/facturaone/v1/get_cart_contents/wp-json/facturaone/v1/get_custom_fields/wp-json/facturaone/v1/create_order/wp-json/facturaone/v1/get_order_details/wp-json/facturaone/v1/get_product_data[fone_add_to_cart][fone_cart][fone_checkout][fone_my_account]