New Order Notification Security & Risk Analysis

wordpress.org/plugins/new-order-popup

New Order Pop-Up Plugin is an alert that will notify you of any new orders that you receive in your WP Admin area.

10 active installs v1.0.0 PHP 5.6+ WP 5.2+ Updated Aug 11, 2022
newordernotificationorderwoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is New Order Notification Safe to Use in 2026?

Generally Safe

Score 85/100

New Order Notification has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "new-order-popup" plugin v1.0.0 exhibits a mixed security posture. On the positive side, it shows no recorded vulnerabilities in its history, and its code analysis reveals no dangerous functions, file operations, or external HTTP requests. Crucially, all SQL queries utilize prepared statements, and a significant majority of output is properly escaped. However, the plugin has a notable weakness in its handling of AJAX requests. It exposes two AJAX handlers, both of which lack authentication checks, creating a direct attack vector. While the taint analysis found no unsanitized paths, the presence of unprotected AJAX endpoints is a significant concern as it bypasses WordPress's built-in security mechanisms.

Key Concerns

  • AJAX handlers without authentication checks
  • Bundled Freemius v1.0 library
Vulnerabilities
None known

New Order Notification Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

New Order Notification Release Timeline

v1.1.0
v1.0.0Current
Code Analysis
Analyzed Mar 17, 2026

New Order Notification Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
42 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

86% escaped49 total outputs
Attack Surface
2 unprotected

New Order Notification Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_check_new_ordernew-order-notification.php:197
noprivwp_ajax_check_new_ordernew-order-notification.php:198
WordPress Hooks 10
actionadmin_menuadmin\inc\nop-settings-page.php:12
filterconnect_urlnew-order-notification.php:78
filterafter_skip_urlnew-order-notification.php:79
filterafter_connect_urlnew-order-notification.php:80
filterafter_pending_connect_urlnew-order-notification.php:81
filterconnect_message_on_updatenew-order-notification.php:124
actionafter_uninstallnew-order-notification.php:125
actionadmin_enqueue_scriptsnew-order-notification.php:193
actionwoocommerce_new_ordernew-order-notification.php:194
actionadmin_footernew-order-notification.php:195
Maintenance & Trust

New Order Notification Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedAug 11, 2022
PHP min version5.6
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

New Order Notification Developer Profile

woodeliveryplugins

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect New Order Notification

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/new-order-popup/assets/css/magnific-nop.css/wp-content/plugins/new-order-popup/assets/js/magnific-nop.min.js/wp-content/plugins/new-order-popup/assets/css/nop-main.css/wp-content/plugins/new-order-popup/assets/js/nop-main.js
Version Parameters
magnific-nop.css?ver=magnific-nop.min.js?ver=nop-main.css?ver=nop-main.js?ver=

HTML / DOM Fingerprints

CSS Classes
nop-notification-settings
HTML Comments
Exit if accessed directlydo stuffsnew order detectionadd new order scripts
Data Attributes
data-pagedata-actiondata-id
JS Globals
nop_new_order_scriptsnop_new_order_detectionnop_woocommerce_new_ordernop_notif_add_scriptsnop_notif_run_deactivatornop_notif_run_activator+2 more
REST Endpoints
/wp-json/nop/v1/check-order
FAQ

Frequently Asked Questions about New Order Notification