
Back In Stock Notifications Security & Risk Analysis
wordpress.org/plugins/back-in-stock-notificationsNotify customers when your products are restocked.
Is Back In Stock Notifications Safe to Use in 2026?
Generally Safe
Score 100/100Back In Stock Notifications has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "back-in-stock-notifications" plugin version 1.0.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for its SQL queries and has no recorded vulnerability history, suggesting a generally stable codebase. The absence of file operations and external HTTP requests also reduces potential attack vectors.
However, there are significant concerns regarding its attack surface. The plugin has one unprotected AJAX handler, which presents a direct entry point for attackers without requiring any authentication or authorization. While there are nonces present, the lack of capability checks on this unprotected handler is a critical oversight. The output escaping is also a concern, with 31% of outputs not being properly escaped, potentially leading to cross-site scripting (XSS) vulnerabilities.
Despite the lack of historical CVEs, the presence of an unprotected AJAX handler and incomplete output escaping represents a tangible risk. The plugin should be updated to include proper authentication and authorization checks for its AJAX endpoints and ensure all outputs are correctly escaped.
Key Concerns
- Unprotected AJAX handler
- Significant unescaped output
- No capability checks on entry points
Back In Stock Notifications Security Vulnerabilities
Back In Stock Notifications Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Back In Stock Notifications Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 14
Maintenance & Trust
Back In Stock Notifications Maintenance & Trust
Maintenance Signals
Community Trust
Back In Stock Notifications Alternatives
MoreConvert Wishlist for WooCommerce
smart-wishlist-for-more-convert
Free: WooCommerce Wishlist, Email automation, Elementor and Premium: Back-in-Stock Notifier, Save For Later, Multi-lists, reports, Email Marketing
AdMail – Multilingual Back in-Stock Notifier for WooCommerce
admail
AdMail is a WooCommerce extension that enables your customers to subscribe to out-of-stock products and receive an email notification when the product …
Alertify – Back in Stock WooCommerce Alerts & Email Notifications
alertify
Alertify - Back in Stock WooCommerce Alerts & Email Notifications
Beltoft In-Stock Notifier for WooCommerce
beltoft-in-stock-notifier
Let customers subscribe to out-of-stock product notifications and automatically email them when items are back in stock.
Stock Notifier Pro For WooCommerce
stock-notifier-pro-for-woocommerce
Never lose a sale due to an out-of-stock product again. Automatically notify your customers when their favorite items are back in stock and recover lo …
Back In Stock Notifications Developer Profile
13 plugins · 510 total installs
How We Detect Back In Stock Notifications
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/back-in-stock-notifications/assets/js/admin-script.js/wp-content/plugins/back-in-stock-notifications/assets/js/admin-script.jsback-in-stock-notifications/assets/js/admin-script.js?ver=1.0.0HTML / DOM Fingerprints
back-in-stock-notifications-wrapbackinst-noticebackinst-successbackinst-errordata-product-idbackinst