Evidence – Social Proof & FOMO Notifications Security & Risk Analysis

wordpress.org/plugins/evidence

Sky rocket conversions with real-time social proof!

60 active installs v1.0.3 PHP 5.6+ WP 5.1+ Updated Feb 2, 2021
conversionnotificationsproofsocialsocial-proof
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Evidence – Social Proof & FOMO Notifications Safe to Use in 2026?

Generally Safe

Score 85/100

Evidence – Social Proof & FOMO Notifications has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The 'evidence' plugin version 1.0.3 demonstrates a generally strong security posture based on the static analysis. It boasts a clean attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events exposed. The code also shows good practices with 100% of SQL queries using prepared statements, zero file operations, and no external HTTP requests. The presence of nonce and capability checks, although minimal (2 each), suggests an awareness of WordPress security mechanisms.

However, the analysis does flag a concern regarding output escaping, with only 40% of outputs being properly escaped. This indicates a potential risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data or dynamic content is outputted without sufficient sanitization. The taint analysis shows no critical or high severity unsanitized flows, which is positive, but the limited number of flows analyzed (2) means this is not exhaustive. The plugin's vulnerability history is clear, with zero recorded CVEs, which implies a lack of past exploitable issues and potentially good developer attention to security. Overall, while the plugin has a low attack surface and good core security practices, the unescaped output is the primary area of concern and requires careful review.

Key Concerns

  • Low output escaping coverage
Vulnerabilities
None known

Evidence – Social Proof & FOMO Notifications Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Evidence – Social Proof & FOMO Notifications Release Timeline

v1.0.3Current
v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

Evidence – Social Proof & FOMO Notifications Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
18
12 escaped
Nonce Checks
2
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

40% escaped30 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
<admin> (templates\admin.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Evidence – Social Proof & FOMO Notifications Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionadmin_menuevidence-plugin.php:55
actionwp_footerevidence-plugin.php:59
actionadmin_initevidence-plugin.php:133
actionadmin_menutrunk\evidence-plugin.php:55
actionwp_footertrunk\evidence-plugin.php:59
actionadmin_inittrunk\evidence-plugin.php:133
Maintenance & Trust

Evidence – Social Proof & FOMO Notifications Maintenance & Trust

Maintenance Signals

WordPress version tested5.6.17
Last updatedFeb 2, 2021
PHP min version5.6
Downloads3K

Community Trust

Rating74/100
Number of ratings3
Active installs60
Developer Profile

Evidence – Social Proof & FOMO Notifications Developer Profile

jarrodevidence

1 plugin · 60 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Evidence – Social Proof & FOMO Notifications

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/evidence/inc//wp-content/plugins/evidence/templates/
Script Paths
/wp-content/plugins/evidence/inc/evidence-plugin-activate.php/wp-content/plugins/evidence/inc/evidence-plugin-deactivate.php

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Evidence – Social Proof & FOMO Notifications