
11za Chat and Notification Security & Risk Analysis
wordpress.org/plugins/11za-chat-and-notificationRecover your lost revenue by sending automatic cart abandonment messages on WhatsApp. Send transaction related updates on WhatsApp.
Is 11za Chat and Notification Safe to Use in 2026?
Generally Safe
Score 100/10011za Chat and Notification has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "11za-chat-and-notification" plugin v1.0.1 exhibits a significantly concerning security posture due to a large number of unprotected entry points. All 4 AJAX handlers and 4 REST API routes lack proper authentication or permission checks, creating a substantial attack surface that is entirely open to unauthenticated users. This is further exacerbated by the presence of the `unserialize` function, a known source of vulnerabilities if used with untrusted input. While the plugin demonstrates good practices in other areas, such as using prepared statements for all SQL queries and a high percentage of properly escaped output, these strengths are overshadowed by the critical flaws in access control.
Key Concerns
- Unprotected AJAX handlers
- Unprotected REST API routes
- Dangerous function (unserialize)
- Taint flow with unsanitized path (high severity)
- Taint flow with unsanitized path (high severity)
- Missing nonce checks on AJAX handlers
- Missing capability checks on entry points
11za Chat and Notification Security Vulnerabilities
11za Chat and Notification Release Timeline
11za Chat and Notification Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
11za Chat and Notification Attack Surface
AJAX Handlers 4
REST API Routes 4
WordPress Hooks 13
Maintenance & Trust
11za Chat and Notification Maintenance & Trust
Maintenance Signals
Community Trust
11za Chat and Notification Alternatives
WATI Chat and Notification
wati-chat-and-notification
Recover your lost revenue by sending automatic cart abandonment messages on WhatsApp. Send transaction related updates on WhatsApp.
CartSaver Chat Recovery
cartsaver-chat-recovery
Recover WooCommerce abandoned carts automatically via Official WhatsApp API or one-click manual links.
MegaSend for WooCommerce
megasend-for-woocommerce
Recover abandoned carts and boost sales with automated WhatsApp messages powered by MegaSend.
Quick Cart Recovery
quick-cart-recovery
Recover lost WooCommerce sales instantly via WhatsApp chat. A lightweight and powerful abandoned cart recovery tool.
ShopNotify – Personalized Cart Recovery for WooCommerce
shopnotify
Track abandoned carts for logged-in and guest users in WooCommerce, send automated WhatsApp reminders, and gain insights into cart recovery and abando …
11za Chat and Notification Developer Profile
1 plugin · 10 total installs
How We Detect 11za Chat and Notification
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/11za-chat-and-notification/modules/cart-abandonment/assets/js/admin-settings.js/wp-content/plugins/11za-chat-and-notification/modules/cart-abandonment/assets/js/cart-abandonment-tracking.js/wp-content/plugins/11za-chat-and-notification/modules/cart-abandonment/assets/css/admin-settings.css/wp-content/plugins/11za-chat-and-notification/modules/cart-abandonment/assets/js/admin-settings.js/wp-content/plugins/11za-chat-and-notification/modules/cart-abandonment/assets/js/cart-abandonment-tracking.jsHTML / DOM Fingerprints
engees-11za-chat-and-notification<!-- 11ZA Chat & Notification -->data-integration-service-urldata-site-iddata-wp-11za-domaindata-api-keyENGEES_11ZA_CARTFLOWS_CART_ABANDONMENT_TRACKING_DIRENGEES_11ZA_CARTFLOWS_CART_ABANDONMENT_TRACKING_URLENGEES_11ZA_CART_ABANDONED_ORDERENGEES_11ZA_CART_COMPLETED_ORDERENGEES_11ZA_CART_LOST_ORDERENGEES_11ZA_CART_NORMAL_ORDER+14 more/wp-json/api/v1/getWoocommerceInfo/wp-json/api/v1/getAccessToken/wp-json/api/v1/getOrderInfo/wp-json/api/v1/getCheckoutInfo