Elite Notification – Sales Popup, Social Proof, FOMO Notification for WooCommerce Security & Risk Analysis

wordpress.org/plugins/elite-notification

ELITE-NOTIFICATION is the best FOMO, Sales Pop-up, Comment, Review & WooCommerce notification with social proof wordpress plugin.

50 active installs v2.0.2 PHP 7.2+ WP 5.2+ Updated Apr 14, 2025
fomonotification-popupsales-notificationsocial-proofwoocommerce-notification
99
A · Safe
CVEs total1
Unpatched0
Last CVEDec 5, 2024
Safety Verdict

Is Elite Notification – Sales Popup, Social Proof, FOMO Notification for WooCommerce Safe to Use in 2026?

Generally Safe

Score 99/100

Elite Notification – Sales Popup, Social Proof, FOMO Notification for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Dec 5, 2024Updated 11mo ago
Risk Assessment

The 'elite-notification' plugin v2.0.2 exhibits a concerning security posture, primarily due to a significant attack surface lacking proper authorization checks. The analysis reveals two AJAX handlers, both of which are exposed without any authentication or capability checks, creating a direct pathway for potential unauthorized actions. While the plugin demonstrates strong output escaping practices and no apparent issues with file operations or chained taint flows, these strengths are overshadowed by the critical vulnerability of unprotected entry points. The presence of the dangerous `unserialize` function without evident sanitization adds another layer of risk, potentially leading to code execution if vulnerable data is processed. Furthermore, the plugin's history includes a medium-severity vulnerability related to missing authorization, reinforcing the ongoing pattern of authorization deficiencies. Although there are no currently unpatched CVEs, the historical pattern suggests a recurring weakness that needs immediate attention. The combination of unprotected AJAX handlers, the use of `unserialize`, and the past authorization issues points to a plugin that requires urgent security review and remediation to mitigate potential exploits.

Key Concerns

  • Unprotected AJAX handlers
  • Dangerous function 'unserialize' used
  • SQL queries without prepared statements
  • Missing nonce checks
  • Missing capability checks
  • 1 medium severity CVE in history
Vulnerabilities
1

Elite Notification – Sales Popup, Social Proof, FOMO Notification for WooCommerce Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-54241medium · 6.3Missing Authorization

Elite Notification – Sales Popup, Social Proof, FOMO & WooCommerce <= 1.5 - Missing Authorization

Dec 5, 2024 Patched in 2.0.0 (127d)
Code Analysis
Analyzed Mar 16, 2026

Elite Notification – Sales Popup, Social Proof, FOMO Notification for WooCommerce Code Analysis

Dangerous Functions
1
Raw SQL Queries
1
0 prepared
Unescaped Output
0
36 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
8
Bundled Libraries
0

Dangerous Functions Found

unserialize$d = unserialize( $body['body'] );elite_notification_lite\api\class-sanl-wordpress-api.php:60

SQL Query Safety

0% prepared1 total queries

Output Escaping

100% escaped36 total outputs
Attack Surface
2 unprotected

Elite Notification – Sales Popup, Social Proof, FOMO Notification for WooCommerce Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_slnf-update-sourceelite_notification_lite\modules\class-elite-notification-source.php:57
noprivwp_ajax_slnf-update-sourceelite_notification_lite\modules\class-elite-notification-source.php:58
WordPress Hooks 22
filterappsbd-slnf-styleselite_notification_lite\modules\class-elite-notification-settings.php:45
actionwp_footerelite_notification_lite\modules\class-elite-notification-settings.php:101
filterslnf-set-nt-byelite_notification_lite\modules\class-elite-notification-settings.php:103
filterquery_varselite_notification_lite\modules\class-elite-notification-settings.php:112
actiontemplate_includeelite_notification_lite\modules\class-elite-notification-settings.php:121
actionapbd-sales-notification/before-load-sourceelite_notification_lite\modules\class-elite-notification-source.php:60
actionapbd-sales-notification/add-sourceelite_notification_lite\modules\class-elite-notification-source.php:61
filterappsbd-slnf-source-categoryelite_notification_lite\modules\class-elite-notification-source.php:63
filtercron_scheduleselite_notification_lite\modules\class-elite-notification-source.php:148
actionappsbd-slnf-load-source-itemelite_notification_lite\modules\class-elite-notification-source.php:149
actionappsbd-slnf-load-source-internallyelite_notification_lite\modules\class-elite-notification-source.php:150
actioncomment_postelite_notification_lite\source\class-ens-comment-source.php:45
actiondeleted_commentelite_notification_lite\source\class-ens-comment-source.php:46
actionedit_commentelite_notification_lite\source\class-ens-comment-source.php:52
actionsave_post_edd_paymentelite_notification_lite\source\class-ens-easy-digital-downloads.php:116
actionsave_postelite_notification_lite\source\class-ens-elearning.php:45
filterslnf_source_grid_itemelite_notification_lite\source\class-ens-fast-spring.php:46
actionsave_post_edd_paymentelite_notification_lite\source\class-ens-give-donation.php:126
actioncomment_postelite_notification_lite\source\class-ens-review-x.php:44
actionsave_postelite_notification_lite\source\class-ens-woocommerce-source.php:50
actionsave_postelite_notification_lite\source\class-ens-wordpress-download-stats.php:45
actionsave_postelite_notification_lite\source\class-ens-wp-review.php:44

Scheduled Events 1

appsbd-slnf-load-source-item
Maintenance & Trust

Elite Notification – Sales Popup, Social Proof, FOMO Notification for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 14, 2025
PHP min version7.2
Downloads5K

Community Trust

Rating100/100
Number of ratings4
Active installs50
Developer Profile

Elite Notification – Sales Popup, Social Proof, FOMO Notification for WooCommerce Developer Profile

appsbd

7 plugins · 3K total installs

87
trust score
Avg Security Score
98/100
Avg Patch Time
68 days
View full developer profile
Detection Fingerprints

How We Detect Elite Notification – Sales Popup, Social Proof, FOMO Notification for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/elite-notification/admin-assets/font.css/wp-content/plugins/elite-notification/cl-assets/css/client-style.css/wp-content/plugins/elite-notification/cl-assets/js/client-script.js
Script Paths
/wp-content/plugins/elite-notification/cl-assets/js/client-script.js
Version Parameters
elite-notification/admin-assets/font.css?ver=elite-notification/cl-assets/css/client-style.css?ver=elite-notification/cl-assets/js/client-script.js?ver=

HTML / DOM Fingerprints

CSS Classes
eln-brand
JS Globals
apbd_en
FAQ

Frequently Asked Questions about Elite Notification – Sales Popup, Social Proof, FOMO Notification for WooCommerce