
Fomo for WooCommerce Security & Risk Analysis
wordpress.org/plugins/fomoFomo displays recent orders on your WooCommerce storefront.
Is Fomo for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Fomo for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'fomo' plugin v2.0.12 presents a generally positive security posture, exhibiting strong practices in several key areas. The complete absence of known CVEs and unpatched vulnerabilities is a significant strength, suggesting a well-maintained and secure development history. Furthermore, the code analysis reveals a robust approach to SQL queries, with 100% utilizing prepared statements, mitigating risks of SQL injection. The use of nonces and capability checks, although present only once each, demonstrates awareness of WordPress security mechanisms for protecting sensitive operations.
However, there are areas that warrant caution. The presence of two 'dangerous functions', specifically `create_function` and `unserialize`, introduces potential risks if not handled with extreme care. `create_function` is deprecated and can lead to code injection if user-supplied data is used in its creation, while `unserialize` is notoriously susceptible to object injection vulnerabilities if the serialized data originates from an untrusted source. The static analysis also indicates that only 64% of output is properly escaped. This leaves a significant portion of output potentially vulnerable to cross-site scripting (XSS) attacks. While the attack surface appears minimal with no unprotected entry points, the combination of these specific code signals raises concerns.
In conclusion, while the plugin benefits from a clean vulnerability history and secure SQL practices, the identified dangerous functions and partially unescaped output are notable weaknesses. These issues, though not currently exploited according to historical data, represent potential avenues for attack. A balanced assessment is that the plugin is likely secure for most use cases, but sites handling highly sensitive data or those that extensively customize plugin output might want to investigate these specific areas further.
Key Concerns
- Presence of 'create_function'
- Presence of 'unserialize'
- Output escaping is not 100%
Fomo for WooCommerce Security Vulnerabilities
Fomo for WooCommerce Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Fomo for WooCommerce Attack Surface
WordPress Hooks 4
Maintenance & Trust
Fomo for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Fomo for WooCommerce Alternatives
Social Proof for WooCommerce
social-proof-for-woocommerce
Motivate your customers to buy from your online store. Show them social proof that other people are already buying from your store.
SalesPulse – Social Proof & FOMO Notifications
salespulse
Boost conversions with real-time social proof & FOMO popups. Show purchases, signups, reviews, visitor counts & announcement bars.
NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar
notificationx
Want to boost business trust & conversions? 97% of visitors hesitate to buy because of credibility. Instantly succeed with WooCommerce Sales Alert!
FOMO & Social Proof Notifications by TrustPulse – Best WordPress FOMO Plugin
trustpulse-api
TrustPulse is a FOMO social proof plugin that leverages the power of social proof to instantly boost site conversions by up to 15%!
ProveSource Social Proof
provesource
ProveSource Social Proof increases conversions by up to 17%, boost trust with woocommerce sales notifications and reviews, increase your credibility!
Fomo for WooCommerce Developer Profile
2 plugins · 30 total installs
How We Detect Fomo for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/fomo/dist/css/fomo.css/wp-content/plugins/fomo/dist/js/fomo.jshttps://fomo.com/api/v1/fomo/dist/css/fomo.css?ver=fomo/dist/js/fomo.js?ver=HTML / DOM Fingerprints
fomofwc-admin-noticefomofwc-main-settings-wrapperfomofwc-fomo-logo<!-- Fomofwc admin notice --><!-- Fomofwc main settings wrapper -->data-fomofwc-client-iddata-fomofwc-consumer-keydata-fomofwc-consumer-secretwindow.fomofwc_settingsvar fomofwc_settings =/wp-json/fomofwc/v1/settings[fomo_display_orders]