ChatasBot – Smart Order Notifications for WooCommerce Security & Risk Analysis

wordpress.org/plugins/chatasbot-order-notifications-woocommerce

Send automated WhatsApp-style order notifications and customer messages in WooCommerce using the ChatasBot platform.

0 active installs v1.0.0 PHP 7.4+ WP 6.0+ Updated Nov 20, 2025
automationchatasbotnotificationswhatsappwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ChatasBot – Smart Order Notifications for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

ChatasBot – Smart Order Notifications for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The "chatasbot-order-notifications-woocommerce" plugin version 1.0.0 exhibits a concerning security posture due to a significant number of unprotected AJAX handlers. While the plugin demonstrates good practices in other areas, such as using prepared statements for all SQL queries and properly escaping all output, the lack of authentication checks on its eight AJAX entry points represents a substantial risk. This could allow unauthenticated users to trigger potentially sensitive actions or expose information through these handlers.

The static analysis reveals no dangerous functions, no file operations, and no external HTTP requests that appear to be immediately problematic without further context. The absence of any recorded vulnerabilities in its history is a positive sign, suggesting a generally stable codebase. However, this does not mitigate the immediate risks posed by the unprotected AJAX handlers. The plugin's strengths lie in its secure handling of database interactions and output, but its weaknesses are starkly highlighted by its attack surface which is entirely unprotected at the AJAX level.

In conclusion, while the plugin has a clean vulnerability history and uses secure coding practices for SQL and output, the critical oversight of not implementing authentication and authorization checks on its AJAX handlers creates a significant security vulnerability. This makes it susceptible to various attacks, and this oversight needs to be addressed to improve its overall security posture.

Key Concerns

  • 8 AJAX handlers without auth checks
Vulnerabilities
None known

ChatasBot – Smart Order Notifications for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

ChatasBot – Smart Order Notifications for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
19 escaped
Nonce Checks
9
Capability Checks
0
File Operations
0
External Requests
5
Bundled Libraries
0

Output Escaping

100% escaped19 total outputs
Attack Surface
8 unprotected

ChatasBot – Smart Order Notifications for WooCommerce Attack Surface

Entry Points8
Unprotected8

AJAX Handlers 8

authwp_ajax_chatasbot_get_order_numbersadmin\settings-page.php:259
authwp_ajax_chatasbot_send_bulk_messageadmin\settings-page.php:319
authwp_ajax_chatasbot_schedule_messageadmin\settings-page.php:354
authwp_ajax_chatasbot_view_scheduleadmin\settings-page.php:380
authwp_ajax_chatasbot_test_connectionadmin\settings-page.php:395
authwp_ajax_chatasbot_send_order_messageincludes\woo-hooks.php:29
authwp_ajax_chatasbot_view_schedule_summaryincludes\woo-hooks.php:115
authwp_ajax_chatasbot_view_subscriptionincludes\woo-hooks.php:130
WordPress Hooks 5
actionadmin_menuadmin\settings-page.php:9
actionadmin_initadmin\settings-page.php:24
actionadmin_enqueue_scriptsadmin\settings-page.php:33
filterwoocommerce_admin_order_actionsincludes\woo-hooks.php:9
actionadmin_noticesincludes\woo-hooks.php:84
Maintenance & Trust

ChatasBot – Smart Order Notifications for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 20, 2025
PHP min version7.4
Downloads133

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

ChatasBot – Smart Order Notifications for WooCommerce Developer Profile

chatasbotofficial

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ChatasBot – Smart Order Notifications for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/chatasbot-order-notifications-woocommerce/admin/css/chatasbot-admin.css/wp-content/plugins/chatasbot-order-notifications-woocommerce/admin/js/chatasbot-admin.js
Version Parameters
chatasbot-order-notifications-woocommerce/admin/css/chatasbot-admin.css?ver=chatasbot-order-notifications-woocommerce/admin/js/chatasbot-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
chatasbot-adminchatasbot-tabschatasbot-tab-contentchatasbot-multiselectchatasbot-manual-numberschatasbot-number-rowchatasbot-manual-inputchatasbot-send-bulk-result
Data Attributes
data-tab
JS Globals
chatasbot_ajax
FAQ

Frequently Asked Questions about ChatasBot – Smart Order Notifications for WooCommerce