
Social Proof Popups & Real-Time Notifications – Herd Effects Security & Risk Analysis
wordpress.org/plugins/mwp-herd-effectBoost conversions with real-time social proof popups and user activity notifications, encouraging visitor actions on your WordPress site.
Is Social Proof Popups & Real-Time Notifications – Herd Effects Safe to Use in 2026?
Generally Safe
Score 96/100Social Proof Popups & Real-Time Notifications – Herd Effects has a strong security track record. Known vulnerabilities have been patched promptly.
The mwp-herd-effect plugin version 6.2.5 presents a mixed security posture. On one hand, the static analysis shows a commendable lack of direct entry points for attackers, with zero AJAX handlers, REST API routes, shortcodes, or cron events that are exposed without authentication. The code also demonstrates strong adherence to secure coding practices, with an impressive 97% of output properly escaped and a high percentage of SQL queries utilizing prepared statements. Furthermore, the absence of file operations and external HTTP requests minimizes common attack vectors.
However, several concerning signals emerge. The taint analysis reveals 10 flows with unsanitized paths, three of which are classified as high severity. This indicates that user-supplied data is not being adequately validated or sanitized before being processed, potentially leading to vulnerabilities. While there are nonce and capability checks present, their limited number in conjunction with the unsanitized flows suggests potential gaps. The plugin's vulnerability history is also a significant concern, with a total of 5 known CVEs, including one high-severity issue and four medium-severity issues, although all are currently patched. The common vulnerability types (CSRF, XSS, PHP RFI) coupled with the recent vulnerability date (2025-01-24) suggest a recurring pattern of exploitable weaknesses that, if not for patching, could have posed serious risks.
In conclusion, while the plugin has made strides in reducing its direct attack surface and adopting secure coding practices for output and database interactions, the presence of unsanitized data flows with high severity taint analysis results and a history of diverse vulnerabilities remain significant security concerns. The plugin's strengths in output escaping and SQL preparation are overshadowed by potential vulnerabilities arising from improper input handling.
Key Concerns
- High severity taint flows found
- Unsanitized paths in taint flows
- 5 known CVEs in vulnerability history
- 1 high severity CVE in history
- 4 medium severity CVEs in history
- Bundled library (TinyMCE)
Social Proof Popups & Real-Time Notifications – Herd Effects Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
Herd Effects <= 6.2.1 - Cross-Site Request Forgery to Settings Update
Herd Effects – fake notifications and social proof plugin <= 5.2.6 - Cross-Site Request Forgery
Herd Effects <= 5.2.2 - Authenticated (Administrator+) Stored Cross-Site Scripting
Herd Effects <= 5.2.3 - Cross-Site Request Forgery to Effect Deletion
Herd Effects <= 5.2 - Local File Inclusion
Social Proof Popups & Real-Time Notifications – Herd Effects Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Social Proof Popups & Real-Time Notifications – Herd Effects Attack Surface
WordPress Hooks 12
Maintenance & Trust
Social Proof Popups & Real-Time Notifications – Herd Effects Maintenance & Trust
Maintenance Signals
Community Trust
Social Proof Popups & Real-Time Notifications – Herd Effects Alternatives
NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar
notificationx
Want to boost business trust & conversions? 97% of visitors hesitate to buy because of credibility. Instantly succeed with WooCommerce Sales Alert!
Real Testimonials – Testimonial Slider, Collect Customer Reviews and Video Testimonials
testimonial-free
A Customizable Testimonial plugin to Automate Collecting, Filtering, and Publishing Customer Reviews. Testimonial Slider, Grid & More to Grow Sales
TrustedSite
trustedsite
Trust badges to increase sales.
FOMO & Social Proof Notifications by TrustPulse – Best WordPress FOMO Plugin
trustpulse-api
TrustPulse is a FOMO social proof plugin that leverages the power of social proof to instantly boost site conversions by up to 15%!
Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity
logtivity
Logtivity is the activity log service for WordPress admins. Logtivity is a unified activity log platform that tracks activity and errors across all yo …
Social Proof Popups & Real-Time Notifications – Herd Effects Developer Profile
25 plugins · 98K total installs
How We Detect Social Proof Popups & Real-Time Notifications – Herd Effects
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mwp-herd-effect/vendors/fontawesome/css/all.min.css/wp-content/plugins/mwp-herd-effect/vendors/fonticonpicker/js/jquery.fonticonpicker.js/wp-content/plugins/mwp-herd-effect/vendors/fonticonpicker/css/jquery.fonticonpicker.css/wp-content/plugins/mwp-herd-effect/vendors/fonticonpicker/themes/bootstrap-4/jquery.fonticonpicker.bootstrap4.min.css/wp-content/plugins/mwp-herd-effect/assets/css/admin.style.css/wp-content/plugins/mwp-herd-effect/assets/js/admin.script.js/wp-content/plugins/mwp-herd-effect/assets/js/public.script.js/wp-content/plugins/mwp-herd-effect/vendors/fontawesome/css/all.min.css/wp-content/plugins/mwp-herd-effect/vendors/fonticonpicker/js/jquery.fonticonpicker.js/wp-content/plugins/mwp-herd-effect/vendors/fonticonpicker/css/jquery.fonticonpicker.css/wp-content/plugins/mwp-herd-effect/vendors/fonticonpicker/themes/bootstrap-4/jquery.fonticonpicker.bootstrap4.min.css/wp-content/plugins/mwp-herd-effect/assets/css/admin.style.css/wp-content/plugins/mwp-herd-effect/assets/js/admin.script.js+1 moremwp-herd-effect/vendors/fontawesome/css/all.min.css?ver=mwp-herd-effect/vendors/fonticonpicker/js/jquery.fonticonpicker.js?ver=mwp-herd-effect/vendors/fonticonpicker/css/jquery.fonticonpicker.css?ver=mwp-herd-effect/vendors/fonticonpicker/themes/bootstrap-4/jquery.fonticonpicker.bootstrap4.min.css?ver=mwp-herd-effect/assets/css/admin.style.css?ver=mwp-herd-effect/assets/js/admin.script.js?ver=mwp-herd-effect/assets/js/public.script.js?ver=HTML / DOM Fingerprints
wow-herd-effectsdata-wow-contentdata-wow-content-iddata-wow-content-nameWOWP_Plugin[Herd-Effects]