{"id":325209,"date":"2026-07-20T18:30:19","date_gmt":"2026-07-20T18:30:19","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/rechnungseingang\/"},"modified":"2026-07-20T18:30:11","modified_gmt":"2026-07-20T18:30:11","slug":"itdatex-e-invoice-intake","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/itdatex-e-invoice-intake\/","author":23515351,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"0.6.5","stable_tag":"0.6.5","tested":"7.0.2","requires":"6.4","requires_php":"8.1","requires_plugins":null,"header_name":"itdatex E-Invoice Intake","header_author":"!tdatex","header_description":"Empfaengt, validiert und archiviert E-Rechnungen (XRechnung, ZUGFeRD, Factur-X) direkt in WordPress. Verarbeitung lokal, ohne Cloud-Upload.","assets_banners_color":"0a0f1a","last_updated":"2026-07-20 18:30:11","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/wp.itdatex.support\/itdatex-e-invoice-intake\/","header_author_uri":"https:\/\/wp.itdatex.support\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":37,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"0.6.5":{"tag":"0.6.5","author":"itdatex","date":"2026-07-20 18:30:11"}},"upgrade_notice":{"0.6.5":"<p>First public release on wp.org.<\/p>","0.6.4":"<p>Follow-up on 0.6.3: broaden phpcs annotation in IngestService so it covers the SQL literal line. No behaviour change.<\/p>","0.6.3":"<p>Playground Plugin Check pass \u2014 sniff-annotation-only changes, no behaviour change.<\/p>","0.6.2":"<p>Trimmed distribution ZIP to satisfy wp.org &quot;not permitted files&quot; review. No behaviour change.<\/p>","0.6.1":"<p>Plugin Check compliance pass \u2014 no behaviour change. Recommended for all users.<\/p>","0.6.0":"<p>Read-only API additions for due-date reporting. No data migration required. Existing setups upgrade in place.<\/p>","0.5.0":"<p>Read-only API addition for export. No data migration required.<\/p>","0.4.0":"<p>Internal refactor: UploadHandler delegates to a new IngestService. Behaviour is unchanged.<\/p>","0.3.0":"<p>New filter and action for add-ons that need to write back into invoice rows. No behavioural change for free-only setups.<\/p>","0.2.0":"<p>Introduces add-on hooks that enable an optional Pro add-on. No behaviour change for free-only installations.<\/p>","0.1.0":"<p>First public release.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3615706,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3615706,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3616024,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3616024,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["0.6.5"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3615706,"resolution":"1","location":"assets","locale":"","width":1280,"height":800},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3615706,"resolution":"2","location":"assets","locale":"","width":1280,"height":800},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3615706,"resolution":"3","location":"assets","locale":"","width":1280,"height":800},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3615706,"resolution":"4","location":"assets","locale":"","width":1280,"height":800},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3615706,"resolution":"5","location":"assets","locale":"","width":1280,"height":800}},"screenshots":{"1":"The inbox view lists all received invoices with format, dates, amounts and a validation status badge.","2":"The single-invoice view shows header data, parties, amounts, validation issues and a complete audit trail in six cards.","3":"The upload form accepts both XML and PDF (ZUGFeRD) files with a single click.","4":"Validation issues are surfaced with severity (error \/ warning \/ info) and the BT\/BR code that triggered them.","5":"The audit trail records every upload, status change and file download."}},"plugin_section":[],"plugin_tags":[2526,247307,12480,263529,263530],"plugin_category":[45],"plugin_contributors":[272517],"plugin_business_model":[],"class_list":["post-325209","plugin","type-plugin","status-publish","hentry","plugin_tags-accounting","plugin_tags-e-invoice","plugin_tags-invoice","plugin_tags-xrechnung","plugin_tags-zugferd","plugin_category-ecommerce","plugin_contributors-itdatex","plugin_committers-itdatex"],"banners":{"banner":"https:\/\/ps.w.org\/itdatex-e-invoice-intake\/assets\/banner-772x250.png?rev=3616024","banner_2x":"https:\/\/ps.w.org\/itdatex-e-invoice-intake\/assets\/banner-1544x500.png?rev=3616024","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/itdatex-e-invoice-intake\/assets\/icon-128x128.png?rev=3615706","icon_2x":"https:\/\/ps.w.org\/itdatex-e-invoice-intake\/assets\/icon-256x256.png?rev=3615706","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/itdatex-e-invoice-intake\/assets\/screenshot-1.png?rev=3615706","caption":"The inbox view lists all received invoices with format, dates, amounts and a validation status badge."},{"src":"https:\/\/ps.w.org\/itdatex-e-invoice-intake\/assets\/screenshot-2.png?rev=3615706","caption":"The single-invoice view shows header data, parties, amounts, validation issues and a complete audit trail in six cards."},{"src":"https:\/\/ps.w.org\/itdatex-e-invoice-intake\/assets\/screenshot-3.png?rev=3615706","caption":"The upload form accepts both XML and PDF (ZUGFeRD) files with a single click."},{"src":"https:\/\/ps.w.org\/itdatex-e-invoice-intake\/assets\/screenshot-4.png?rev=3615706","caption":"Validation issues are surfaced with severity (error \/ warning \/ info) and the BT\/BR code that triggered them."},{"src":"https:\/\/ps.w.org\/itdatex-e-invoice-intake\/assets\/screenshot-5.png?rev=3615706","caption":"The audit trail records every upload, status change and file download."}],"raw_content":"<!--section=description-->\n<p>Since 1 January 2025, all businesses in Germany must be able to receive electronic invoices (e-invoices) under \u00a7 14 UStG. By 2027\/2028 they must also issue them. Most existing tools require uploading sensitive supplier data \u2014 amounts, VAT IDs, bank details \u2014 to a third-party cloud service. <strong>itdatex E-Invoice Intake<\/strong> does the work locally inside your own WordPress installation.<\/p>\n\n<h4>What it does<\/h4>\n\n<ul>\n<li>Accepts XRechnung (UBL and UN\/CEFACT\/CII), ZUGFeRD (hybrid PDF\/A-3 with embedded XML) and Factur-X via drag-and-drop upload<\/li>\n<li>Detects the format automatically and parses the core fields: invoice number, dates, seller and buyer, VAT ID, totals (net\/tax\/gross), positions, buyer reference (Leitweg-ID)<\/li>\n<li>Validates against the embedded EN-16931 XML schema and checks for required fields (BT-1, BT-2, BT-27, BT-112)<\/li>\n<li>Stores each file with a random name in a protected upload directory and chains every file's SHA-256 with the previous one (revision-evidence)<\/li>\n<li>Provides a human-readable single-invoice view with header data, parties, amounts, validation issues and an audit trail<\/li>\n<li>Logs every action (upload, status change, download) in a dedicated audit table<\/li>\n<\/ul>\n\n<h4>Privacy by design<\/h4>\n\n<p>The free version performs all processing locally on your own server. No data leaves your WordPress installation. There is no telemetry, no automatic update check against a third party, no analytics, no external font or asset loading.<\/p>\n\n<p>A separate Pro version (sold via wp.itdatex.support, not part of this free plugin) adds optional cloud-assisted features \u2014 KoSIT deep validation, AI-based error explanations in plain German, IMAP auto-import, DATEV export \u2014 and is opt-in only.<\/p>\n\n<h4>GoBD-supporting, not GoBD-certified<\/h4>\n\n<p>The plugin supports GoBD-conformant processes through immutable storage, SHA-256 hash chaining and a complete audit trail. Note that software cannot be \"GoBD-certified\" \u2014 conformity is a property of <em>your<\/em> process, not of any single tool. Consult your tax advisor for the specifics of your setup.<\/p>\n\n<h4>Open source<\/h4>\n\n<p>The full source code is released under GPL-2.0-or-later. You can verify, audit and adapt the plugin yourself. Dependencies (josemmo\/einvoicing for UBL, horstoeko\/zugferd for CII\/ZUGFeRD) are vendored with prefixed namespaces so they cannot conflict with other plugins in the same WordPress installation.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin folder to <code>\/wp-content\/plugins\/itdatex-e-invoice-intake\/<\/code>, or install via the Plugins screen.<\/li>\n<li>Activate the plugin.<\/li>\n<li>Open the \"Rechnungen\" menu in the admin sidebar. You can upload your first XRechnung or ZUGFeRD file straight away.<\/li>\n<\/ol>\n\n<p>The plugin creates three database tables (<code>*_reing_invoices<\/code>, <code>*_reing_files<\/code>, <code>*_reing_audit_log<\/code>) and a protected upload directory under <code>wp-content\/uploads\/itdatex-e-invoice-intake-{random}\/<\/code>. On uninstall, <strong>invoice data and files are NOT deleted by default<\/strong> because of statutory retention requirements (8 to 10 years under German tax and commercial law).<\/p>\n\n<p>To force a full cleanup on uninstall, add this line to your <code>wp-config.php<\/code> <em>before<\/em> deleting the plugin:<\/p>\n\n<pre><code>define( 'REING_UNINSTALL_DELETE_ALL', true );\n<\/code><\/pre>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20the%20plugin%20send%20anything%20to%20your%20server%3F\"><h3>Does the plugin send anything to your server?<\/h3><\/dt>\n<dd><p>The free version makes no external HTTP calls. All parsing, validation and storage happens locally in your WordPress installation. You can verify this by inspecting the source \u2014 the only network code path is the optional Pro upgrade, which is not part of this plugin.<\/p><\/dd>\n<dt id=\"which%20formats%20are%20supported%3F\"><h3>Which formats are supported?<\/h3><\/dt>\n<dd><p>XRechnung in both UBL and UN\/CEFACT (CII) syntax, ZUGFeRD from version 2.0.1 onwards (PDF\/A-3 with embedded XML), and Factur-X. Pure PDFs without an embedded XML payload are recognized as \"legacy PDF\" and stored as files, but their fields can only be extracted with the optional Pro AI extraction.<\/p><\/dd>\n<dt id=\"is%20this%20gobd-conformant%3F\"><h3>Is this GoBD-conformant?<\/h3><\/dt>\n<dd><p>The plugin provides the technical foundation \u2014 immutable storage, hash chain, audit log \u2014 that a GoBD-conformant process requires. Whether your concrete bookkeeping process is GoBD-conformant is a question for your tax advisor and depends on more than just the software you use. We deliberately do NOT advertise \"GoBD certification\" because no such certification mechanism exists in Germany.<\/p><\/dd>\n<dt id=\"can%20i%20delete%20invoices%3F\"><h3>Can I delete invoices?<\/h3><\/dt>\n<dd><p>You can mark invoices as paid or disputed. Physically deleting invoices in WordPress is intentionally not exposed in the UI to protect the integrity of the hash chain. If you have a legal reason to delete (e.g. erroneous double-upload), please use direct database access and document the deletion in your retention log.<\/p><\/dd>\n<dt id=\"what%20about%20the%20upload%20size%20limit%3F\"><h3>What about the upload size limit?<\/h3><\/dt>\n<dd><p>The plugin uses the WordPress \/ PHP upload size limit (<code>upload_max_filesize<\/code>, <code>post_max_size<\/code>). XRechnung files are typically well below 1 MB; ZUGFeRD PDFs can reach a few MB. If you need higher limits, increase them in your <code>php.ini<\/code> or <code>.htaccess<\/code>.<\/p><\/dd>\n<dt id=\"does%20this%20work%20behind%20nginx%3F\"><h3>Does this work behind nginx?<\/h3><\/dt>\n<dd><p>Yes. The protected upload directory uses both <code>.htaccess<\/code> (Apache\/LiteSpeed) and a randomized directory name so that path guessing fails. File downloads always go through a capability-and-nonce-checked endpoint, never via a direct URL \u2014 so the front-end web server's authorization model is irrelevant for the file path security.<\/p><\/dd>\n<dt id=\"why%20no%20wp-cron%20%2F%20imap%20%2F%20datev%20export%3F\"><h3>Why no WP-Cron \/ IMAP \/ DATEV export?<\/h3><\/dt>\n<dd><p>These are paid features in the Pro version. The free version focuses on the core legal requirement \u2014 receiving and archiving incoming e-invoices \u2014 and keeps the dependency surface small to make security review easy.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>0.6.5<\/h4>\n\n<ul>\n<li>First public release on wp.org. XRechnung and ZUGFeRD parsing (UBL 2.1, UN\/CEFACT CII, PDF\/A-3 with embedded XML), KoSIT-based field validation, secure server-side storage with a tamper-evident hash chain, upload UI, invoice inbox, single-invoice detail view, secure download endpoint, and a full audit log. WP-CLI commands for headless ingest.<\/li>\n<\/ul>\n\n<h4>0.6.4<\/h4>\n\n<ul>\n<li>Replaced the single-line <code>phpcs:ignore<\/code> around the duplicate-check query in <code>IngestService::ingest()<\/code> with a <code>phpcs:disable<\/code>\/<code>phpcs:enable<\/code> block so the sniff annotation also covers the interpolated SQL literal on the following line. No behaviour change.<\/li>\n<\/ul>\n\n<h4>0.6.3<\/h4>\n\n<ul>\n<li>Playground Plugin Check compliance pass: rename lexical include-scoped variables to the <code>reing_<\/code> prefix in <code>uninstall.php<\/code> and the bootstrap file so the sniff no longer flags them; wrap the three admin view files (<code>page-inbox.php<\/code>, <code>page-invoice.php<\/code>, <code>page-upload.php<\/code>) with a <code>phpcs:disable WordPress.NamingConventions.PrefixAllGlobals.NonPrefixedVariableFound<\/code> block explaining that the vars are template-locals, not globals. Annotated the read-only <code>$_GET<\/code> accesses in <code>Admin\\Pages\\Invoice<\/code> and <code>Admin\\Pages\\Inbox<\/code> with <code>phpcs:ignore WordPress.Security.NonceVerification.Recommended<\/code> (display-only, all writes go through nonce-protected admin-post endpoints). Annotated the duplicate-check <code>$wpdb-&gt;get_var()<\/code> in <code>IngestService<\/code> (table-name accessor, no user input). Gated the <code>error_log()<\/code> call in the same file behind <code>WP_DEBUG<\/code>. Annotated <code>$_FILES['invoice_file']<\/code> in <code>UploadHandler<\/code> (cannot be sanitized like a string; validated by Parser + Validator downstream). Rewrote the uninstall <code>DROP TABLE<\/code> loop with a phpcs:ignore + rationale for uninstall-time schema removal.<\/li>\n<\/ul>\n\n<h4>0.6.2<\/h4>\n\n<ul>\n<li>wp.org Plugin Review round 2: distribution ZIP no longer ships the schema assets (<code>*.xslt<\/code>, <code>*.sch<\/code>, <code>*.xmp<\/code>) from the bundled <code>horstoeko\/zugferd<\/code> library nor the Sphinx docs from <code>jms\/serializer<\/code> \u2014 they are not used at runtime by the free plugin (validation runs against KoSIT in the optional Pro backend). Removed the unused, outdated transitive <code>setasign\/fpdf 1.9<\/code> dependency entirely. Annotated the two remaining static SQL statements in <code>InvoiceRepository::lastChainHash()<\/code> and <code>countInvoices()<\/code> with rationale.<\/li>\n<\/ul>\n\n<h4>0.6.1<\/h4>\n\n<ul>\n<li>Plugin Check compliance pass: escape interpolated exception messages (<code>FormatDetector<\/code>, <code>Parser<\/code>, <code>Storage<\/code>, <code>InvoiceRepository<\/code>), replace <code>is_writable()<\/code> with <code>wp_is_writable()<\/code>, <code>unlink()<\/code> with <code>wp_delete_file()<\/code>, <code>rmdir()<\/code> with <code>WP_Filesystem::rmdir()<\/code>, drop best-effort <code>chmod()<\/code> on stored invoices, inline SQL in <code>listOpenInvoices()<\/code> to satisfy the prepared-SQL sniff, annotate the dynamic <code>listForExport<\/code> query and the streaming <code>readfile()<\/code> in the download endpoint. No behaviour change.<\/li>\n<\/ul>\n\n<h4>0.6.0<\/h4>\n\n<ul>\n<li>New API: <code>InvoiceRepository::listOpenInvoices()<\/code> and <code>summarizeOpenInvoices()<\/code> for due-date reporting and aggregation by bucket (overdue \/ this week \/ this month \/ later \/ no date). Used by the optional Pro dashboard.<\/li>\n<\/ul>\n\n<h4>0.5.0<\/h4>\n\n<ul>\n<li>New API: <code>InvoiceRepository::listForExport($from, $to, $status, $limit)<\/code> with safe date range and status filter for CSV\/DATEV exporters. Used by the optional Pro export module.<\/li>\n<\/ul>\n\n<h4>0.4.0<\/h4>\n\n<ul>\n<li>New service class <code>IngestService::ingest($path, $name, $source, $actor)<\/code> encapsulating the parse \u2192 validate \u2192 store \u2192 audit pipeline. UploadHandler refactored to use it. Enables add-ons (e.g. Pro IMAP import) to reuse the exact same processing chain that the browser upload uses, including the existing hooks.<\/li>\n<\/ul>\n\n<h4>0.3.0<\/h4>\n\n<ul>\n<li>New filter <code>reing_applyable_fields<\/code> and action <code>reing_apply_invoice_fields($id, $fields, $source)<\/code> to allow add-ons to update invoice fields with type-safe sanitisation. Adds <code>InvoiceRepository::applyableFields()<\/code> and <code>updateFields()<\/code> with date \/ amount \/ currency normalisation. Sets <code>extracted_by = 'ai_draft'<\/code> and writes a structured audit entry.<\/li>\n<\/ul>\n\n<h4>0.2.0<\/h4>\n\n<ul>\n<li>Add-on integration hooks: <code>reing_after_validate($tmpPath, $report, $invoiceData)<\/code>, <code>reing_after_invoice_insert($id, $invoiceData, $report)<\/code> and <code>reing_invoice_view_after_validation($invoice, $reportData)<\/code> allow optional Pro extensions to plug in deep validation, AI explanations and extra UI cards without modifying the free core. Includes a small backup autoloader for the prefixed Smalot\/PdfParser library that the Strauss-generated PSR-0 mapping does not resolve correctly.<\/li>\n<\/ul>\n\n<h4>0.1.0<\/h4>\n\n<ul>\n<li>Initial release: parsing, validation, storage with hash chain, upload, inbox and single-invoice views, secure download endpoint, audit log.<\/li>\n<\/ul>","raw_excerpt":"Receive, parse and archive German e-invoices (XRechnung, ZUGFeRD, Factur-X) directly in WordPress \u2014 without uploading them to any cloud.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/325209","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=325209"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/itdatex"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=325209"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=325209"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=325209"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=325209"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=325209"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=325209"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}