
Evidence – Social Proof & FOMO Notifications Security & Risk Analysis
wordpress.org/plugins/evidenceSky rocket conversions with real-time social proof!
Is Evidence – Social Proof & FOMO Notifications Safe to Use in 2026?
Generally Safe
Score 85/100Evidence – Social Proof & FOMO Notifications has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'evidence' plugin version 1.0.3 demonstrates a generally strong security posture based on the static analysis. It boasts a clean attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events exposed. The code also shows good practices with 100% of SQL queries using prepared statements, zero file operations, and no external HTTP requests. The presence of nonce and capability checks, although minimal (2 each), suggests an awareness of WordPress security mechanisms.
However, the analysis does flag a concern regarding output escaping, with only 40% of outputs being properly escaped. This indicates a potential risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data or dynamic content is outputted without sufficient sanitization. The taint analysis shows no critical or high severity unsanitized flows, which is positive, but the limited number of flows analyzed (2) means this is not exhaustive. The plugin's vulnerability history is clear, with zero recorded CVEs, which implies a lack of past exploitable issues and potentially good developer attention to security. Overall, while the plugin has a low attack surface and good core security practices, the unescaped output is the primary area of concern and requires careful review.
Key Concerns
- Low output escaping coverage
Evidence – Social Proof & FOMO Notifications Security Vulnerabilities
Evidence – Social Proof & FOMO Notifications Release Timeline
Evidence – Social Proof & FOMO Notifications Code Analysis
Output Escaping
Data Flow Analysis
Evidence – Social Proof & FOMO Notifications Attack Surface
WordPress Hooks 6
Maintenance & Trust
Evidence – Social Proof & FOMO Notifications Maintenance & Trust
Maintenance Signals
Community Trust
Evidence – Social Proof & FOMO Notifications Alternatives
Social Proof Popups & Real-Time Notifications – Herd Effects
mwp-herd-effect
Boost conversions with real-time social proof popups and user activity notifications, encouraging visitor actions on your WordPress site.
Sales Push Notification
sales-push-notification
Boost conversions with real-time sales notifications that build trust and create FOMO. Customizable, WooCommerce-compatible, and mobile-friendly.
SocialProofus Notifications
socialproofus
Boost Your Online Presence with SocialProofus Notifications: Drive Engagement and Credibility! - 100% free!
ProofBlazer
proofblazer
ProofBlazer is a social proof marketing platform that helps boost trust and conversions by displaying real-time notifications on your WordPress site.
SalesPulse – Social Proof & FOMO Notifications
salespulse
Boost conversions with real-time social proof & FOMO popups. Show purchases, signups, reviews, visitor counts & announcement bars.
Evidence – Social Proof & FOMO Notifications Developer Profile
1 plugin · 60 total installs
How We Detect Evidence – Social Proof & FOMO Notifications
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/evidence/inc//wp-content/plugins/evidence/templates//wp-content/plugins/evidence/inc/evidence-plugin-activate.php/wp-content/plugins/evidence/inc/evidence-plugin-deactivate.php