
Notifications for Forms & WordPress Actions Security & Risk Analysis
wordpress.org/plugins/notifierSend WhatsApp notifications for form submissions from CF7, Gravity Forms, WPForms and more and WordPress actions using WhatsApp Business API
Is Notifications for Forms & WordPress Actions Safe to Use in 2026?
Generally Safe
Score 96/100Notifications for Forms & WordPress Actions has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'notifier' plugin version 2.7.13 exhibits a mixed security posture. While it demonstrates good practices with a high percentage of prepared SQL statements and properly escaped output, there are concerning signals. The presence of unsanitized paths in the taint analysis, particularly a high-severity flow, is a significant risk. This indicates a potential for attackers to manipulate file paths or other inputs that are not adequately validated, which could lead to various security issues like unauthorized file access or manipulation.
The vulnerability history for 'notifier' is a major concern, with three known CVEs, two of which remain unpatched. The common vulnerability types, Missing Authorization and Cross-site Scripting (XSS), directly correlate with the potential risks identified in the static analysis, especially the unsanitized path flow. The fact that the last vulnerability was dated in the future (2026-01-20) is likely a data anomaly but the historical trend of past vulnerabilities is concerning. The plugin's attack surface, while protected by authorization checks for its AJAX handlers, still presents entry points that, when combined with past vulnerabilities and current taint analysis findings, warrant careful consideration.
In conclusion, 'notifier' v2.7.13 has strengths in its SQL and output handling but suffers from critical weaknesses. The unpatched vulnerabilities and the identified unsanitized path flow represent immediate threats. Users of this plugin should be aware of the historical and current risks and prioritize updating to a version that addresses these issues, if available, or consider alternatives. The plugin's historical pattern of authorization and XSS vulnerabilities, coupled with the current taint analysis, suggests a recurring need for diligent security auditing and patching.
Key Concerns
- Unpatched CVEs
- High severity taint flow with unsanitized path
- Bundled library (Select2) without version check
Notifications for Forms & WordPress Actions Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
WANotifier <= 2.7.13 - Missing Authorization
WANotifier <= 2.7.12 - Missing Authorization
WANotifier – Send Message Notifications Using WhatsApp API <= 2.6 - Authenticated (Admin+) Stored Cross-Site Scripting
Notifications for Forms & WordPress Actions Release Timeline
Notifications for Forms & WordPress Actions Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Notifications for Forms & WordPress Actions Attack Surface
AJAX Handlers 6
WordPress Hooks 65
Maintenance & Trust
Notifications for Forms & WordPress Actions Maintenance & Trust
Maintenance Signals
Community Trust
Notifications for Forms & WordPress Actions Alternatives
Notiqoo – Order Notification & Customer Chat for WooCommerce
wc-messaging
Send WooCommerce WhatsApp notifications via official WhatsApp API for instant order updates, customer chat, and abandoned cart recovery
Abandoned Checkout Recovery & Order Notifications for WooCommerce
abandoned-checkout-recovery-order-notifications-for-woocommerce
Send WhatsApp notifications for recovering abandoned carts, double confirming CoD orders and for other order & shipment updates! Also, send out yo …
Order & Abandoned Cart Notifications for WooCommerce
order-notifications-for-woocommerce
Send WhatsApp notifications for WooCommerce orders, order status updates and abandoned cart recovery using the official WhatsApp Business API.
Message Notification for Contact Form 7
message-notification-for-contact-form-7
Get a notification on WhatsApp instantly when someone submits the Contact Form 7(CF7). Database & Email not needed. 100% Free. No pro version.
Click to Chat – HoliThemes
click-to-chat-for-whatsapp
WhatsApp Chat🔥. Let's make your Web page visitors contact you through 'WhatsApp', 'WhatsApp Business'. Add matching Widget✅
Notifications for Forms & WordPress Actions Developer Profile
2 plugins · 1K total installs
How We Detect Notifications for Forms & WordPress Actions
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/notifier/assets/js/select2.min.js/wp-content/plugins/notifier/assets/js/admin.js/wp-content/plugins/notifier/assets/css/admin.css/wp-content/plugins/notifier/assets/css/frontend.css/wp-content/plugins/notifier/assets/js/select2.min.js/wp-content/plugins/notifier/assets/js/admin.jsnotifier/assets/js/select2.min.js?ver=notifier/assets/js/admin.js?ver=notifier/assets/css/admin.css?ver=notifier/assets/css/frontend.css?ver=HTML / DOM Fingerprints
notifier-modal-contentnotifier-modal-headernotifier-modal-bodynotifier-modal-footernotifier-titlenotifier-settings-sectionnotifier-switchnotifier-input-field+15 more<!-- Start of Notifier Settings --><!-- End of Notifier Settings --><!-- Start of Notifier Activity Log --><!-- End of Notifier Activity Log -->+7 moredata-notifier-modal-targetdata-notifier-modal-closedata-notifier-trigger-iddata-notifier-trigger-statusnotifierObj/wp-json/notifier/v1/settings/wp-json/notifier/v1/activity-logs/wp-json/notifier/v1/triggers[notifier_settings][notifier_activity_log][notifier_dashboard][notifier_triggers]