KhudeBarta Order Notify Security & Risk Analysis

wordpress.org/plugins/khudebarta-order-notify

Send SMS via KhudeBarta API and notify customers automatically when WooCommerce order statuses change.

0 active installs v2.1.4 PHP 7.2+ WP 5.0+ Updated Dec 22, 2025
bdsmskhudebartaorder-notificationorder-statuswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is KhudeBarta Order Notify Safe to Use in 2026?

Generally Safe

Score 100/100

KhudeBarta Order Notify has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The 'khudebarta-order-notify' plugin version 2.1.4 exhibits a strong security posture based on the provided static analysis. The plugin demonstrates excellent adherence to secure coding practices, notably the absence of dangerous functions, file operations, and external HTTP requests. The critical finding is the complete absence of raw SQL queries, with all 100% utilizing prepared statements, which significantly mitigates SQL injection risks. Furthermore, the overwhelming majority of output is properly escaped, and the plugin implements nonce and capability checks for its entry points, indicating a deliberate effort to secure against common attack vectors. The zero known CVEs and historical absence of vulnerabilities further reinforce this positive security outlook.

Despite the generally robust security, a minor concern exists regarding the external HTTP request, as while not inherently vulnerable, such requests can sometimes be a vector for vulnerabilities if not handled with extreme care and proper validation. The static analysis also indicates a small attack surface consisting of one AJAX handler, but reassuringly, it is protected by authentication checks, eliminating immediate concerns for direct unauthorized access through this channel. The taint analysis showing zero unsanitized paths further solidifies the plugin's security. Overall, the plugin is well-secured, with its strengths far outweighing any minor potential risks.

Key Concerns

  • Presence of an external HTTP request
Vulnerabilities
None known

KhudeBarta Order Notify Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

KhudeBarta Order Notify Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
23 escaped
Nonce Checks
3
Capability Checks
3
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

92% escaped25 total outputs
Attack Surface

KhudeBarta Order Notify Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_khudorno_send_smskhudebarta-order-notify.php:24
WordPress Hooks 9
actionadmin_menukhudebarta-order-notify.php:22
actionadmin_enqueue_scriptskhudebarta-order-notify.php:23
actionwoocommerce_order_status_processingkhudebarta-order-notify.php:27
actionwoocommerce_order_status_completedkhudebarta-order-notify.php:28
actionwoocommerce_order_status_pendingkhudebarta-order-notify.php:29
actionwoocommerce_order_status_failedkhudebarta-order-notify.php:30
actionwoocommerce_order_status_on-holdkhudebarta-order-notify.php:31
actionwoocommerce_order_status_refundedkhudebarta-order-notify.php:32
actionwoocommerce_order_status_cancelledkhudebarta-order-notify.php:33
Maintenance & Trust

KhudeBarta Order Notify Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 22, 2025
PHP min version7.2
Downloads145

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

KhudeBarta Order Notify Developer Profile

HR Hasib

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect KhudeBarta Order Notify

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/khudebarta-order-notify/assets/admin.css/wp-content/plugins/khudebarta-order-notify/assets/admin.js
Script Paths
/wp-content/plugins/khudebarta-order-notify/assets/admin.js
Version Parameters
khudebarta-order-notify/assets/admin.css?ver=khudebarta-order-notify/assets/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
khudorno-gridkhudorno-textarea
Data Attributes
data-bs-toggledata-bs-target
JS Globals
KHUDORNO_SMS
REST Endpoints
/wp-json/khudebarta-order-notify/v1/send-sms
FAQ

Frequently Asked Questions about KhudeBarta Order Notify