Social Proof Popups & Real-Time Notifications – Herd Effects Security & Risk Analysis

wordpress.org/plugins/mwp-herd-effect

Boost conversions with real-time social proof popups and user activity notifications, encouraging visitor actions on your WordPress site.

1K active installs v6.2.5 PHP 7.4+ WP 5.0+ Updated Dec 2, 2025
conversion-boostpopup-notificationsreal-time-notificationssocial-proofuser-activity
96
A · Safe
CVEs total5
Unpatched0
Last CVEJan 24, 2025
Safety Verdict

Is Social Proof Popups & Real-Time Notifications – Herd Effects Safe to Use in 2026?

Generally Safe

Score 96/100

Social Proof Popups & Real-Time Notifications – Herd Effects has a strong security track record. Known vulnerabilities have been patched promptly.

5 known CVEsLast CVE: Jan 24, 2025Updated 4mo ago
Risk Assessment

The mwp-herd-effect plugin version 6.2.5 presents a mixed security posture. On one hand, the static analysis shows a commendable lack of direct entry points for attackers, with zero AJAX handlers, REST API routes, shortcodes, or cron events that are exposed without authentication. The code also demonstrates strong adherence to secure coding practices, with an impressive 97% of output properly escaped and a high percentage of SQL queries utilizing prepared statements. Furthermore, the absence of file operations and external HTTP requests minimizes common attack vectors.

However, several concerning signals emerge. The taint analysis reveals 10 flows with unsanitized paths, three of which are classified as high severity. This indicates that user-supplied data is not being adequately validated or sanitized before being processed, potentially leading to vulnerabilities. While there are nonce and capability checks present, their limited number in conjunction with the unsanitized flows suggests potential gaps. The plugin's vulnerability history is also a significant concern, with a total of 5 known CVEs, including one high-severity issue and four medium-severity issues, although all are currently patched. The common vulnerability types (CSRF, XSS, PHP RFI) coupled with the recent vulnerability date (2025-01-24) suggest a recurring pattern of exploitable weaknesses that, if not for patching, could have posed serious risks.

In conclusion, while the plugin has made strides in reducing its direct attack surface and adopting secure coding practices for output and database interactions, the presence of unsanitized data flows with high severity taint analysis results and a history of diverse vulnerabilities remain significant security concerns. The plugin's strengths in output escaping and SQL preparation are overshadowed by potential vulnerabilities arising from improper input handling.

Key Concerns

  • High severity taint flows found
  • Unsanitized paths in taint flows
  • 5 known CVEs in vulnerability history
  • 1 high severity CVE in history
  • 4 medium severity CVEs in history
  • Bundled library (TinyMCE)
Vulnerabilities
5

Social Proof Popups & Real-Time Notifications – Herd Effects Security Vulnerabilities

CVEs by Year

1 CVE in 2022
2022
2 CVEs in 2023
2023
1 CVE in 2024
2024
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

High
1
Medium
4

5 total CVEs

CVE-2025-24716medium · 4.3Cross-Site Request Forgery (CSRF)

Herd Effects <= 6.2.1 - Cross-Site Request Forgery to Settings Update

Jan 24, 2025 Patched in 6.2.2 (5d)
CVE-2024-3478medium · 4.3Cross-Site Request Forgery (CSRF)

Herd Effects – fake notifications and social proof plugin <= 5.2.6 - Cross-Site Request Forgery

Apr 11, 2024 Patched in 5.2.7 (27d)
CVE-2023-4022medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Herd Effects <= 5.2.2 - Authenticated (Administrator+) Stored Cross-Site Scripting

Aug 21, 2023 Patched in 5.2.3 (155d)
CVE-2023-4318medium · 4.3Cross-Site Request Forgery (CSRF)

Herd Effects <= 5.2.3 - Cross-Site Request Forgery to Effect Deletion

Aug 21, 2023 Patched in 5.2.4 (155d)
CVE-2022-29448high · 7.2Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

Herd Effects <= 5.2 - Local File Inclusion

May 16, 2022 Patched in 5.2.1 (617d)
Code Analysis
Analyzed Mar 16, 2026

Social Proof Popups & Real-Time Notifications – Herd Effects Code Analysis

Dangerous Functions
0
Raw SQL Queries
7
20 prepared
Unescaped Output
8
297 escaped
Nonce Checks
2
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

TinyMCE

SQL Query Safety

74% prepared27 total queries

Output Escaping

97% escaped305 total outputs
Data Flows
10 unsanitized

Data Flow Analysis

10 flows10 with unsanitized paths
menu (classes\Admin\Dashboard.php:164)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Social Proof Popups & Real-Time Notifications – Herd Effects Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actionadmin_initclasses\Admin\AdminActions.php:23
actionadmin_noticesclasses\Admin\AdminNotices.php:13
filterplugin_action_linksclasses\Admin\Dashboard.php:25
filterplugin_row_metaclasses\Admin\Dashboard.php:26
filteradmin_footer_textclasses\Admin\Dashboard.php:27
actionadmin_enqueue_scriptsclasses\Admin\Dashboard.php:28
actionadmin_menuclasses\Admin\Dashboard.php:29
actionadmin_menuincludes\class-wow-company.php:20
actionadmin_enqueue_scriptsincludes\class-wow-company.php:21
actionplugins_loadedmwp-herd-effect.php:70
actionwp_enqueue_scriptspublic\class-wowp-public.php:37
actionwp_footerpublic\class-wowp-public.php:38
Maintenance & Trust

Social Proof Popups & Real-Time Notifications – Herd Effects Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 2, 2025
PHP min version7.4
Downloads60K

Community Trust

Rating78/100
Number of ratings15
Active installs1K
Developer Profile

Social Proof Popups & Real-Time Notifications – Herd Effects Developer Profile

Wow-Company

25 plugins · 98K total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
236 days
View full developer profile
Detection Fingerprints

How We Detect Social Proof Popups & Real-Time Notifications – Herd Effects

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mwp-herd-effect/vendors/fontawesome/css/all.min.css/wp-content/plugins/mwp-herd-effect/vendors/fonticonpicker/js/jquery.fonticonpicker.js/wp-content/plugins/mwp-herd-effect/vendors/fonticonpicker/css/jquery.fonticonpicker.css/wp-content/plugins/mwp-herd-effect/vendors/fonticonpicker/themes/bootstrap-4/jquery.fonticonpicker.bootstrap4.min.css/wp-content/plugins/mwp-herd-effect/assets/css/admin.style.css/wp-content/plugins/mwp-herd-effect/assets/js/admin.script.js/wp-content/plugins/mwp-herd-effect/assets/js/public.script.js
Script Paths
/wp-content/plugins/mwp-herd-effect/vendors/fontawesome/css/all.min.css/wp-content/plugins/mwp-herd-effect/vendors/fonticonpicker/js/jquery.fonticonpicker.js/wp-content/plugins/mwp-herd-effect/vendors/fonticonpicker/css/jquery.fonticonpicker.css/wp-content/plugins/mwp-herd-effect/vendors/fonticonpicker/themes/bootstrap-4/jquery.fonticonpicker.bootstrap4.min.css/wp-content/plugins/mwp-herd-effect/assets/css/admin.style.css/wp-content/plugins/mwp-herd-effect/assets/js/admin.script.js+1 more
Version Parameters
mwp-herd-effect/vendors/fontawesome/css/all.min.css?ver=mwp-herd-effect/vendors/fonticonpicker/js/jquery.fonticonpicker.js?ver=mwp-herd-effect/vendors/fonticonpicker/css/jquery.fonticonpicker.css?ver=mwp-herd-effect/vendors/fonticonpicker/themes/bootstrap-4/jquery.fonticonpicker.bootstrap4.min.css?ver=mwp-herd-effect/assets/css/admin.style.css?ver=mwp-herd-effect/assets/js/admin.script.js?ver=mwp-herd-effect/assets/js/public.script.js?ver=

HTML / DOM Fingerprints

CSS Classes
wow-herd-effects
Data Attributes
data-wow-contentdata-wow-content-iddata-wow-content-name
JS Globals
WOWP_Plugin
Shortcode Output
[Herd-Effects]
FAQ

Frequently Asked Questions about Social Proof Popups & Real-Time Notifications – Herd Effects