FOMO Notifications Security & Risk Analysis

wordpress.org/plugins/fomo-notifications

Display real-time WooCommerce sales notifications to boost social proof and increase conversions.

0 active installs v1.0.0 PHP 7.4+ WP 6.0+ Updated Mar 30, 2025
ecommercefomosales-notificationwoocommerce
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is FOMO Notifications Safe to Use in 2026?

Generally Safe

Score 92/100

FOMO Notifications has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "fomo-notifications" v1.0.0 plugin demonstrates a generally good security posture, with robust implementation of several key security practices. The absence of any known CVEs and the strong emphasis on prepared statements for SQL queries are positive indicators. Furthermore, the high percentage of properly escaped output and the presence of nonce and capability checks on its entry points suggest an awareness of common web vulnerabilities.

However, the static analysis did reveal potential areas for improvement. Specifically, the "taint analysis" flagged two flows with unsanitized paths. While these did not escalate to critical or high severity, they represent a potential avenue for attackers to inject malicious data. The presence of file operations without further context is also a mild concern, as these can sometimes be exploited if not carefully managed. The overall lack of documented vulnerabilities is reassuring, implying the developers have historically maintained a secure codebase.

In conclusion, "fomo-notifications" v1.0.0 is a relatively secure plugin with a solid foundation. The most significant concern lies in the two identified unsanitized path flows, which, while not currently critical, warrant attention. The plugin benefits from strong input validation and output escaping practices. A continuous security review and prompt patching of any future vulnerabilities would further solidify its security.

Key Concerns

  • Flows with unsanitized paths found
  • File operations present
Vulnerabilities
None known

FOMO Notifications Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

FOMO Notifications Release Timeline

v1.0.0Current
Code Analysis
Analyzed Mar 17, 2026

FOMO Notifications Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
203 escaped
Nonce Checks
6
Capability Checks
1
File Operations
4
External Requests
0
Bundled Libraries
1

Bundled Libraries

TinyMCE

Output Escaping

98% escaped207 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

3 flows2 with unsanitized paths
save_post (includes\admin\class-fomo-notifications-admin-notification-ui.php:228)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

FOMO Notifications Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

noprivwp_ajax_fomo_notifications_get_notificationsincludes\global\class-fomo-notifications-output.php:30
authwp_ajax_fomo_notifications_get_notificationsincludes\global\class-fomo-notifications-output.php:31
WordPress Hooks 28
actionwp_insert_sitefomo-notifications.php:74
actionwpmu_new_blogfomo-notifications.php:76
actionactivate_blogfomo-notifications.php:78
filterwpzinc_admin_body_classincludes\admin\class-fomo-notifications-admin-notification-ui.php:49
actionadmin_enqueue_scriptsincludes\admin\class-fomo-notifications-admin-notification-ui.php:50
actionadd_meta_boxesincludes\admin\class-fomo-notifications-admin-notification-ui.php:53
actionsave_postincludes\admin\class-fomo-notifications-admin-notification-ui.php:56
actionfomo_notifications_admin_settings_enqueue_stylesincludes\admin\class-fomo-notifications-admin-section-general.php:64
actionadmin_enqueue_scriptsincludes\admin\class-fomo-notifications-admin-settings.php:44
actionadmin_enqueue_scriptsincludes\admin\class-fomo-notifications-admin-settings.php:45
actionadmin_menuincludes\admin\class-fomo-notifications-admin-settings.php:46
actionadmin_initincludes\admin\class-fomo-notifications-admin-settings.php:47
actioninitincludes\class-fomo-notifications.php:87
actionfomo_notifications_admin_settings_add_settings_pageincludes\class-fomo-notifications.php:90
actionwp_enqueue_scriptsincludes\global\class-fomo-notifications-output.php:34
actionwp_footerincludes\global\class-fomo-notifications-output.php:35
filterfomo_notifications_output_get_notifications_conditions_metincludes\global\class-fomo-notifications-output.php:38
actioninitincludes\global\class-fomo-notifications-post-type.php:39
filterfomo_notifications_admin_notification_ui_get_sourcesincludes\sources\class-fomo-notifications-source-woocommerce.php:47
filterfomo_notifications_admin_notification_ui_get_display_fieldsincludes\sources\class-fomo-notifications-source-woocommerce.php:50
filterfomo_notifications_notification_settings_get_defaultsincludes\sources\class-fomo-notifications-source-woocommerce.php:51
filteradmin_body_class_modules\dashboard\class-wpzincdashboardwidget.php:123
actionadmin_enqueue_scripts_modules\dashboard\class-wpzincdashboardwidget.php:124
actionadmin_notices_modules\dashboard\class-wpzincdashboardwidget.php:137
filteradmin_footer_text_modules\dashboard\class-wpzincdashboardwidget.php:138
actioninit_modules\dashboard\class-wpzincdashboardwidget.php:142
actionplugins_loaded_modules\dashboard\class-wpzincdashboardwidget.php:143
filterallowed_redirect_hosts_modules\dashboard\class-wpzincdashboardwidget.php:146
Maintenance & Trust

FOMO Notifications Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedMar 30, 2025
PHP min version7.4
Downloads311

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

FOMO Notifications Developer Profile

wpzinc

6 plugins · 12K total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
378 days
View full developer profile
Detection Fingerprints

How We Detect FOMO Notifications

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/fomo-notifications/assets/css/admin/fomo-notifications-admin.css/wp-content/plugins/fomo-notifications/assets/js/admin/fomo-notifications-admin.js
Version Parameters
fomo-notifications/assets/css/admin/fomo-notifications-admin.css?ver=fomo-notifications/assets/js/admin/fomo-notifications-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
fomo-notification
FAQ

Frequently Asked Questions about FOMO Notifications