SyncMate Order Notifications Security & Risk Analysis

wordpress.org/plugins/assistro-order-notifications

WooCommerce Order Notifications. Automatically send WhatsApp messages to customers when their order status changes.

0 active installs v1.0.6 PHP 7.4+ WP 6.4+ Updated Mar 9, 2026
automationjwtorder-notificationswhatsappwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is SyncMate Order Notifications Safe to Use in 2026?

Generally Safe

Score 100/100

SyncMate Order Notifications has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 26d ago
Risk Assessment

The "assistro-order-notifications" plugin v1.0.6 presents a generally good security posture based on the provided static analysis. The plugin exhibits excellent practices by having no identified AJAX handlers, REST API routes, shortcodes, or cron events that could serve as entry points for attackers. Furthermore, the absence of dangerous functions and file operations is a significant strength. The use of prepared statements for all SQL queries is also a commendable practice, mitigating SQL injection risks.

However, there are areas for improvement. The plugin has a low percentage of properly escaped output (68%), indicating a potential risk for Cross-Site Scripting (XSS) vulnerabilities. While taint analysis shows no critical or high severity flows, the unescaped outputs could still be exploited in specific scenarios. The plugin also makes three external HTTP requests, which, without further analysis, represent a potential attack vector if those external services are compromised or manipulated. The single nonce check and zero capability checks are also concerning, as these are crucial for ensuring that actions are authorized and intended.

The vulnerability history is a strong positive point, with zero recorded CVEs of any severity. This suggests a historically stable and secure plugin. However, the lack of recorded vulnerabilities should not lead to complacency, especially given the identified weaknesses in output escaping and the minimal use of authorization checks. The plugin's strengths lie in its limited attack surface and secure data handling for SQL, but the lack of robust authorization and output sanitization poses a risk that needs attention.

Key Concerns

  • Low percentage of properly escaped output
  • Zero capability checks
  • Only one nonce check
  • Three external HTTP requests
Vulnerabilities
None known

SyncMate Order Notifications Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

SyncMate Order Notifications Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
13
28 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
3
Bundled Libraries
0

Output Escaping

68% escaped41 total outputs
Attack Surface

SyncMate Order Notifications Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_menuincludes\class-admin-settings.php:10
actionadmin_initincludes\class-admin-settings.php:11
actionadmin_enqueue_scriptsincludes\class-admin-settings.php:12
actionwoocommerce_order_status_changedincludes\class-order-hooks.php:8
actionwoocommerce_order_status_changedincludes\class-order-hooks.php:9
Maintenance & Trust

SyncMate Order Notifications Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 9, 2026
PHP min version7.4
Downloads392

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

SyncMate Order Notifications Developer Profile

heratassistro

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SyncMate Order Notifications

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/assistro-order-notifications/assets/css/admin-style.css/wp-content/plugins/assistro-order-notifications/assets/js/admin-script.js
Script Paths
/wp-content/plugins/assistro-order-notifications/assets/js/admin-script.js
Version Parameters
assistro-order-notifications/assets/css/admin-style.css?ver=assistro-order-notifications/assets/js/admin-script.js?ver=

HTML / DOM Fingerprints

CSS Classes
nav-tab-wrappernav-tabnav-tab-active
Data Attributes
id="wawp_country_mode"id="wawp_country_code"
JS Globals
WAWP_URL
FAQ

Frequently Asked Questions about SyncMate Order Notifications