Chat notifications for Woocommerce Security & Risk Analysis

wordpress.org/plugins/chat-notifications-for-woocommerce

Chat notifications for Woocommerce, allows users to automatically send WhatsApp custom templates to your customers when an Order status is updated.

0 active installs v1.0.6 PHP + WP 4.0.1+ Updated Apr 17, 2024
whatsappwhatsapp-order-notificationswoocommerce-notificationswoocommerce-order-notificationswoocommerce-whatsapp
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Chat notifications for Woocommerce Safe to Use in 2026?

Generally Safe

Score 92/100

Chat notifications for Woocommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "chat-notifications-for-woocommerce" plugin, in version 1.0.6, exhibits a concerning security posture primarily due to a significant number of unprotected AJAX entry points. While the plugin demonstrates good practices in database interactions by exclusively using prepared statements and has no recorded vulnerability history, the lack of authentication and capability checks on all identified AJAX handlers presents a substantial risk.

The static analysis reveals an attack surface of 4 AJAX handlers, all of which are unprotected. This means any unauthenticated user could potentially interact with these handlers, leading to unintended actions or information disclosure. Although the taint analysis did not reveal critical or high severity unsanitized paths, the presence of flows with unsanitized paths (albeit not critical) combined with unprotected entry points is a recipe for potential exploitation. The moderate output escaping (46% properly escaped) also suggests a risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not handled carefully within the unprotected AJAX endpoints.

In conclusion, the plugin's reliance on prepared statements for SQL and its clean vulnerability history are positive indicators of developer diligence in certain areas. However, the critical weakness lies in the unprotected AJAX handlers. This oversight creates a wide attack vector that outweighs the other strengths, making the plugin a potential target for attackers seeking to exploit unauthenticated functionalities. Addressing these unprotected AJAX handlers with proper authentication and capability checks is paramount to improving its security.

Key Concerns

  • Unprotected AJAX handlers
  • Unescaped output present
  • Flows with unsanitized paths (non-critical)
  • No nonce checks on AJAX
  • No capability checks
Vulnerabilities
None known

Chat notifications for Woocommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Chat notifications for Woocommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
21
18 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

46% escaped39 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

3 flows3 with unsanitized paths
wafwc_save_template_config (admin\class-chat-notifications-for-woocommerce-admin.php:243)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
4 unprotected

Chat notifications for Woocommerce Attack Surface

Entry Points4
Unprotected4

AJAX Handlers 4

authwp_ajax_wafwc_save_new_templateincludes\class-chat-notifications-for-woocommerce.php:165
noprivwp_ajax_wafwc_save_new_templateincludes\class-chat-notifications-for-woocommerce.php:166
authwp_ajax_wafwc_save_template_configincludes\class-chat-notifications-for-woocommerce.php:168
noprivwp_ajax_wafwc_save_template_configincludes\class-chat-notifications-for-woocommerce.php:169
WordPress Hooks 8
actionplugins_loadedincludes\class-chat-notifications-for-woocommerce.php:142
actionadmin_enqueue_scriptsincludes\class-chat-notifications-for-woocommerce.php:157
actionadmin_enqueue_scriptsincludes\class-chat-notifications-for-woocommerce.php:158
actionadmin_menuincludes\class-chat-notifications-for-woocommerce.php:159
actionwoocommerce_order_status_changedincludes\class-chat-notifications-for-woocommerce.php:160
filterwoocommerce_checkout_create_orderincludes\class-chat-notifications-for-woocommerce.php:187
actionwp_enqueue_scriptsincludes\class-chat-notifications-for-woocommerce.php:190
actionwp_enqueue_scriptsincludes\class-chat-notifications-for-woocommerce.php:191
Maintenance & Trust

Chat notifications for Woocommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedApr 17, 2024
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Chat notifications for Woocommerce Developer Profile

algaweb

2 plugins · 0 total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Chat notifications for Woocommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/chat-notifications-for-woocommerce/css/chat-notifications-for-woocommerce-admin.css/wp-content/plugins/chat-notifications-for-woocommerce/js/chat-notifications-for-woocommerce-admin.js/wp-content/plugins/chat-notifications-for-woocommerce/js/chat-notifications-for-woocommerce-admin-templates.js
Version Parameters
/chat-notifications-for-woocommerce/css/chat-notifications-for-woocommerce-admin.css?ver=/chat-notifications-for-woocommerce/js/chat-notifications-for-woocommerce-admin.js?ver=/chat-notifications-for-woocommerce/js/chat-notifications-for-woocommerce-admin-templates.js?ver=

HTML / DOM Fingerprints

JS Globals
wafwc_save_template_config
FAQ

Frequently Asked Questions about Chat notifications for Woocommerce