
MyBotify Security & Risk Analysis
wordpress.org/plugins/mybotifySend automatic WhatsApp notifications for orders, updates, and more. Perfect for WooCommerce stores and WordPress sites!
Is MyBotify Safe to Use in 2026?
Generally Safe
Score 100/100MyBotify has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The mybotify plugin v1.0.2 exhibits a strong security posture with no recorded vulnerabilities and excellent adherence to secure coding practices in static analysis. All identified entry points (AJAX handlers, REST API routes, cron events) appear to have proper authentication and permission checks, and all output is correctly escaped, eliminating risks associated with Cross-Site Scripting (XSS) and arbitrary code execution through output manipulation. The absence of dangerous functions, file operations, and taint analysis findings further strengthens this positive assessment.
However, a few areas warrant attention. The plugin utilizes 33 SQL queries, with 52% not using prepared statements. While the lack of unescaped output mitigates direct SQL injection risks from data display, inefficient or less secure SQL handling can still lead to performance issues or expose vulnerabilities if combined with other factors. Additionally, the plugin makes two external HTTP requests, which could be a vector for SSRF vulnerabilities if the target URLs are not carefully validated and sanitized, although no such issues were flagged in the provided data. The complete absence of capability checks on the entry points is a potential concern, as it implies that access control is solely reliant on WordPress's built-in role and capability management, which might not be granular enough for all use cases. Despite these minor points, the plugin's history of zero vulnerabilities suggests a development team committed to security.
Key Concerns
- SQL queries not using prepared statements
- External HTTP requests present
- No explicit capability checks on entry points
MyBotify Security Vulnerabilities
MyBotify Release Timeline
MyBotify Code Analysis
SQL Query Safety
Output Escaping
MyBotify Attack Surface
AJAX Handlers 4
REST API Routes 2
WordPress Hooks 14
Scheduled Events 2
Maintenance & Trust
MyBotify Maintenance & Trust
Maintenance Signals
Community Trust
MyBotify Alternatives
BULK SMS PLANS SMS Notifications
bulksmsplans-sms-notifications
Send custom SMS and WhatsApp notifications for WooCommerce orders, with tracking of sent messages.
SyncMate Order Notifications
assistro-order-notifications
WooCommerce Order Notifications. Automatically send WhatsApp messages to customers when their order status changes via the Assistro platform.
Chat notifications for Woocommerce
chat-notifications-for-woocommerce
Chat notifications for Woocommerce, allows users to automatically send WhatsApp custom templates to your customers when an Order status is updated.
GoRespond for WooCommerce
gorespond-for-woocommerce
Automatically send WhatsApp messages to customers when order events happen — powered by GoRespond.
MegaSend for WooCommerce
megasend-for-woocommerce
Recover abandoned carts and boost sales with automated WhatsApp messages powered by MegaSend.
MyBotify Developer Profile
4 plugins · 910 total installs
How We Detect MyBotify
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mybotify/Assets/Css/mybotify-admin.css/wp-content/plugins/mybotify/Assets/Js/mybotify-admin-settings.js/wp-content/plugins/mybotify/Assets/Js/mybotify-admin-settings.jsmybotify/Assets/Css/mybotify-admin.css?ver=mybotify/Assets/Js/mybotify-admin-settings.js?ver=HTML / DOM Fingerprints
data-mybotifymybotify_admin_ajax_object/wp-json/mybotify/v1/notification-list/wp-json/mybotify/v1/sync-mybotify-triggers