Order Notifications for WooCommerce Security & Risk Analysis

wordpress.org/plugins/discord-notifications-for-woocommerce

Get real-time WooCommerce order notifications on Discord, Telegram, Slack, SMS, and Email.

60 active installs v2.0.2 PHP 7.4+ WP 5.0+ Updated Sep 14, 2025
discordnotificationsorderstelegramwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Order Notifications for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Order Notifications for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The "discord-notifications-for-woocommerce" v2.0.2 plugin exhibits a generally good security posture with several positive indicators. The absence of known CVEs, reliance on prepared statements for all SQL queries, and a very high percentage of properly escaped output are strong points. Furthermore, the limited use of dangerous functions, file operations, and the presence of nonces and capability checks contribute to a robust defense. However, a key concern arises from the attack surface. With a total of 4 entry points, 2 of which are REST API routes lacking permission callbacks, there's a clear risk of unauthorized access or manipulation if these endpoints are not properly secured at the application or server level. While taint analysis did not reveal any immediate exploitable flows, the unprotected REST API routes present a potential avenue for attackers to inject data that could be processed insecurely, especially if the application logic relies on user-supplied data within these endpoints. The plugin's history of zero vulnerabilities is a positive sign, suggesting good development practices, but the current unprotected REST API routes require careful attention.

Key Concerns

  • REST API routes without permission callbacks
Vulnerabilities
None known

Order Notifications for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Order Notifications for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
32 escaped
Nonce Checks
2
Capability Checks
5
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

97% escaped33 total outputs
Attack Surface
2 unprotected

Order Notifications for WooCommerce Attack Surface

Entry Points4
Unprotected2

AJAX Handlers 2

authwp_ajax_discord_woo_notif_dismiss_review_noticeinc\Admin\ReviewNotice.php:41
authwp_ajax_discord_woo_notif_reset_review_noticeinc\Admin\ReviewNotice.php:47

REST API Routes 2

GET/wp-json/discord-woo-notif/v1/settingsinc\API\SettingsController.php:14
GET/wp-json/discord-woo-notif/v1/templatesinc\API\SettingsController.php:31
WordPress Hooks 13
actionplugins_loadeddiscord-notifications-for-woocommerce.php:38
actionadmin_initinc\Admin\ReviewNotice.php:33
actionadmin_headinc\Admin\ReviewNotice.php:36
actionadmin_noticesinc\Admin\ReviewNotice.php:40
actionadmin_enqueue_scriptsinc\Admin\ReviewNotice.php:42
actionadmin_menuinc\Admin\Settings.php:9
actionadmin_enqueue_scriptsinc\Admin\Settings.php:11
actionrest_api_initinc\Admin\Settings.php:12
actionadmin_noticesinc\Plugin.php:77
actionwoocommerce_new_orderinc\Provider\Discord\DiscordProvider.php:16
actionwoocommerce_order_status_changedinc\Provider\Discord\DiscordProvider.php:17
actionwoocommerce_new_orderinc\Provider\Telegram\TelegramProvider.php:16
actionwoocommerce_order_status_changedinc\Provider\Telegram\TelegramProvider.php:17
Maintenance & Trust

Order Notifications for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 14, 2025
PHP min version7.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs60
Developer Profile

Order Notifications for WooCommerce Developer Profile

Kamal Hosen

9 plugins · 1K total installs

88
trust score
Avg Security Score
91/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Order Notifications for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/discord-notifications-for-woocommerce/assets/css/admin-notice.css/wp-content/plugins/discord-notifications-for-woocommerce/assets/js/admin-notice.js
Script Paths
/wp-content/plugins/discord-notifications-for-woocommerce/assets/js/admin-notice.js
Version Parameters
/wp-content/plugins/discord-notifications-for-woocommerce/assets/css/admin-notice.css?ver=/wp-content/plugins/discord-notifications-for-woocommerce/assets/js/admin-notice.js?ver=

HTML / DOM Fingerprints

CSS Classes
discord-woo-notif-review-noticediscord-woo-notif-app
HTML Comments
<!-- Review Notice class --><!-- Number of days to wait before showing the notice --><!-- Option name for storing first activation time --><!-- Option name for storing notice dismissal -->+19 more
Data Attributes
id="discord-woo-notif-review-notice"id="discord-woo-notif-app"
JS Globals
discord_woo_notif_dismiss_review_noticediscord_woo_notif_reset_review_notice
FAQ

Frequently Asked Questions about Order Notifications for WooCommerce