ClickBank Sale Notification Security & Risk Analysis

wordpress.org/plugins/clickbank-sale-notification

ClickBank Sale Notification plugin will automatically send you an email notification every time there is a transaction in your ClickBank account.

10 active installs v0.120508 PHP + WP 2.5+ Updated May 9, 2012
clickbanksale-notification
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ClickBank Sale Notification Safe to Use in 2026?

Generally Safe

Score 85/100

ClickBank Sale Notification has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

The "clickbank-sale-notification" plugin, in version 0.120508, exhibits a generally poor security posture, despite a lack of reported vulnerabilities or critical code analysis findings. The static analysis reveals a complete absence of any entry points such as AJAX handlers, REST API routes, shortcodes, or cron events that would typically expose functionality to external interaction. This, combined with zero identified dangerous functions, raw SQL queries, or external HTTP requests, suggests a very limited or non-existent direct attack surface. However, this apparent lack of vulnerabilities is overshadowed by significant concerns in code quality and input sanitization. Specifically, a concerning 100% of its 8 output operations are not properly escaped, presenting a high risk of Cross-Site Scripting (XSS) vulnerabilities. The presence of file operations without any apparent input validation or sanitization also raises red flags, potentially leading to arbitrary file read or write vulnerabilities. The complete lack of nonce and capability checks further exacerbates these risks, meaning any code that does execute could be triggered by any user, regardless of their privileges, and without proper authorization.

Key Concerns

  • 0% output escaping
  • No capability checks
  • No nonce checks
  • File operations without context
Vulnerabilities
None known

ClickBank Sale Notification Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

ClickBank Sale Notification Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
2
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped8 total outputs
Attack Surface

ClickBank Sale Notification Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_noticesclickbank-sale-notification.php:14
actionadmin_menuclickbank-sale-notification.php:48
actionadmin_initclickbank-sale-notification.php:64
Maintenance & Trust

ClickBank Sale Notification Maintenance & Trust

Maintenance Signals

WordPress version tested3.3.2
Last updatedMay 9, 2012
PHP min version
Downloads5K

Community Trust

Rating74/100
Number of ratings3
Active installs10
Developer Profile

ClickBank Sale Notification Developer Profile

poer

2 plugins · 40 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ClickBank Sale Notification

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
icon32
HTML Comments
copy notify.php to root folder on plugin activation delete copy og notify.php in the root folder on plugin uninstall/delete add new menu into WordPress admin menu Init plugin options to white list our options +7 more
Data Attributes
name="cbsn_secret_key"id="cbsn_secret_key"name="cbsn_email"id="cbsn_email"name="cbsn_save"id="cbsn_save"
JS Globals
pk_cbsn_validate_form_0trim
FAQ

Frequently Asked Questions about ClickBank Sale Notification