Atlas Dynamic Messages for WooCommerce Security & Risk Analysis

wordpress.org/plugins/atlas-dynamic-messages-for-woocommerce

Real-time dynamic countdown messages that work perfectly with ALL caching plugins - LiteSpeed Cache, WP Rocket, W3 Total Cache, Cloudflare, and more!

0 active installs v2.4.3 PHP 7.4+ WP 5.0+ Updated Dec 7, 2025
countdownshippingtimerurgencywoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Atlas Dynamic Messages for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Atlas Dynamic Messages for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The plugin "atlas-dynamic-messages-for-woocommerce" v2.4.3 exhibits a mixed security posture. On the positive side, the plugin demonstrates strong adherence to secure coding practices. All identified SQL queries utilize prepared statements, ensuring protection against SQL injection. Furthermore, all output is properly escaped, mitigating cross-site scripting (XSS) vulnerabilities. The absence of file operations and external HTTP requests also reduces potential attack vectors. A single nonce check and two capability checks are present, indicating some level of access control.

However, a significant concern arises from the plugin's attack surface. With one REST API route identified that lacks a permission callback, this presents a clear, unprotected entry point. While the taint analysis shows no flows with unsanitized paths, the existence of an unprotected REST API endpoint is a critical flaw that could be exploited. The vulnerability history is clean, with no recorded CVEs, which is a positive indicator of the plugin's historical security. Nevertheless, the lack of historical vulnerabilities does not negate the immediate risk posed by the unprotected REST API endpoint.

In conclusion, while the plugin generally follows good security practices concerning SQL and output handling, the unprotected REST API endpoint is a serious vulnerability that needs immediate attention. This single exposed endpoint significantly elevates the risk profile of the plugin. It is crucial to address this exposed REST API route to improve the overall security of the plugin.

Key Concerns

  • REST API route without permission callback
Vulnerabilities
None known

Atlas Dynamic Messages for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Atlas Dynamic Messages for WooCommerce Release Timeline

v2.4.3Current
v2.4.2
v2.4.1
v2.4.0
Code Analysis
Analyzed Apr 16, 2026

Atlas Dynamic Messages for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
324 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped324 total outputs
Attack Surface
1 unprotected

Atlas Dynamic Messages for WooCommerce Attack Surface

Entry Points1
Unprotected1

REST API Routes 1

GET/wp-json/atlas-dmsg/v1/infopublic/class-atlas-dynamic-messages-public.php:221
WordPress Hooks 13
actionadmin_menuadmin/class-atlas-dynamic-messages-admin.php:36
actionadmin_initadmin/class-atlas-dynamic-messages-admin.php:37
actionadmin_enqueue_scriptsadmin/class-atlas-dynamic-messages-admin.php:38
actionadmin_noticesatlas-dynamic-messages-for-woocommerce.php:41
actionadmin_initatlas-dynamic-messages-for-woocommerce.php:45
actionbefore_woocommerce_initatlas-dynamic-messages-for-woocommerce.php:64
actionadmin_noticesincludes/class-atlas-dynamic-messages.php:102
actionwp_enqueue_scriptspublic/class-atlas-dynamic-messages-public.php:59
actionwp_enqueue_scriptspublic/class-atlas-dynamic-messages-public.php:60
actionrest_api_initpublic/class-atlas-dynamic-messages-public.php:61
actionwoocommerce_before_single_productpublic/class-atlas-dynamic-messages-public.php:64
actionwoocommerce_before_cartpublic/class-atlas-dynamic-messages-public.php:65
actionwoocommerce_before_checkout_formpublic/class-atlas-dynamic-messages-public.php:66
Maintenance & Trust

Atlas Dynamic Messages for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 7, 2025
PHP min version7.4
Downloads455

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Atlas Dynamic Messages for WooCommerce Developer Profile

Plugin Atlas

2 plugins · 20 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Atlas Dynamic Messages for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/atlas-dynamic-messages-for-woocommerce/admin/css/jquery-ui-tabs.min.css/wp-content/plugins/atlas-dynamic-messages-for-woocommerce/admin/css/admin-style.css/wp-content/plugins/atlas-dynamic-messages-for-woocommerce/admin/js/admin-script.js
Version Parameters
atlas-dmsg-admin-style?ver=atlas-dmsg-admin-script?ver=

HTML / DOM Fingerprints

JS Globals
atlasDmsgAdmin
FAQ

Frequently Asked Questions about Atlas Dynamic Messages for WooCommerce