Beep Notifier – Live Sales Notification for WooCommerce Security & Risk Analysis

wordpress.org/plugins/beep-notifier

Show recent WooCommerce sales as live notifications to boost conversions and create social proof. Increase urgency and drive more sales!

0 active installs v1.0.0 PHP + WP 5.2+ Updated Mar 9, 2025
live-salenotificationnotifiersale-notificationwoocommerce-sales
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Beep Notifier – Live Sales Notification for WooCommerce Safe to Use in 2026?

Generally Safe

Score 92/100

Beep Notifier – Live Sales Notification for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The 'beep-notifier' v1.0.0 plugin exhibits a generally positive security posture due to strong adherence to best practices in several key areas. The code analysis reveals excellent practices, with 100% of SQL queries utilizing prepared statements and 100% of output being properly escaped. This significantly mitigates risks related to SQL injection and Cross-Site Scripting (XSS). Furthermore, the absence of known vulnerabilities in its history suggests a stable and well-maintained codebase over time. The plugin also correctly implements nonce and capability checks in some entry points, which is a good defense mechanism.

However, the plugin presents a notable security concern regarding its attack surface. It exposes two AJAX handlers, both of which lack authentication checks. This is a significant risk as it allows any authenticated user, regardless of their role or permissions, to trigger these functionalities. While taint analysis did not reveal any unsanitized flows, the presence of unprotected AJAX endpoints creates a clear vulnerability that could be exploited if these handlers perform sensitive actions or expose information.

In conclusion, 'beep-notifier' v1.0.0 demonstrates strengths in secure coding practices for data handling and output. Its clean vulnerability history is also a positive indicator. The primary weakness lies in the unprotected AJAX endpoints, which represent a substantial security gap. Addressing these unprotected entry points should be the immediate priority for improving the plugin's security.

Key Concerns

  • AJAX handlers without auth checks
  • AJAX handlers without auth checks
Vulnerabilities
None known

Beep Notifier – Live Sales Notification for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Beep Notifier – Live Sales Notification for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
157 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

100% escaped157 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
beep_save_plugin_settings (admin\class-beep-notifier-admin-action.php:12)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Beep Notifier – Live Sales Notification for WooCommerce Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_beep_get_recent_salesincludes\class-beep-notifier.php:212
noprivwp_ajax_beep_get_recent_salesincludes\class-beep-notifier.php:213
WordPress Hooks 11
actionadmin_post_beep_save_settingsadmin\class-beep-notifier-admin-action.php:9
actionadmin_menuadmin\class-beep-notifier-admin-menu.php:28
actionadmin_initbeep-notifier.php:45
actionplugins_loadedincludes\class-beep-notifier.php:173
actionadmin_enqueue_scriptsincludes\class-beep-notifier.php:188
actionadmin_enqueue_scriptsincludes\class-beep-notifier.php:189
actionadmin_headincludes\class-beep-notifier.php:190
filterplugin_action_links_includes\class-beep-notifier.php:191
actionwp_enqueue_scriptsincludes\class-beep-notifier.php:209
actionwp_enqueue_scriptsincludes\class-beep-notifier.php:210
actionwp_footerincludes\class-beep-notifier.php:211
Maintenance & Trust

Beep Notifier – Live Sales Notification for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedMar 9, 2025
PHP min version
Downloads485

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

Beep Notifier – Live Sales Notification for WooCommerce Developer Profile

BeepCoder

2 plugins · 10 total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Beep Notifier – Live Sales Notification for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/beep-notifier/admin/css/bootstrap.min.css/wp-content/plugins/beep-notifier/admin/css/sweetalert2.min.css/wp-content/plugins/beep-notifier/admin/css/select2.min.css/wp-content/plugins/beep-notifier/admin/css/beep-notifier-admin.css/wp-content/plugins/beep-notifier/admin/js/bootstrap.bundle.min.js/wp-content/plugins/beep-notifier/admin/js/sweetalert2.all.min.js/wp-content/plugins/beep-notifier/admin/js/select2.min.js/wp-content/plugins/beep-notifier/admin/js/beep-notifier-admin.js
Version Parameters
beep-notifier/admin/css/bootstrap.min.css?ver=beep-notifier/admin/css/sweetalert2.min.css?ver=beep-notifier/admin/css/select2.min.css?ver=beep-notifier/admin/css/beep-notifier-admin.css?ver=beep-notifier/admin/js/bootstrap.bundle.min.js?ver=beep-notifier/admin/js/sweetalert2.all.min.js?ver=beep-notifier/admin/js/select2.min.js?ver=beep-notifier/admin/js/beep-notifier-admin.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Beep Notifier – Live Sales Notification for WooCommerce