Notify Bot for WooCommerce Security & Risk Analysis

wordpress.org/plugins/notify-bot-woocommerce

Notify Bot for WooCommerce: Streamline Order Management Effortlessly

100 active installs v2.5.3 PHP 7.4+ WP 6.7+ Updated Dec 3, 2025
notificationtelegramwoocommercewoocommerce-notifier
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Notify Bot for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Notify Bot for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The plugin exhibits a concerning security posture due to a significant number of unprotected entry points. With 3 total entry points, all 3 (AJAX handlers and REST API routes) lack proper authentication or permission checks. This creates a wide attack surface, making it vulnerable to unauthorized access and manipulation. While the plugin demonstrates good practices in SQL query handling by exclusively using prepared statements and avoids known dangerous functions, the lack of output escaping on 70% of outputs is a significant weakness that could lead to cross-site scripting (XSS) vulnerabilities. The absence of nonce checks further exacerbates the risk associated with these entry points. The plugin's history of zero known vulnerabilities is positive, suggesting a potentially diligent development team or perhaps limited exposure. However, this lack of history should not overshadow the critical security flaws identified in the current static analysis.

Key Concerns

  • Unprotected AJAX handlers
  • Unprotected REST API routes
  • Missing nonce checks
  • Insufficient output escaping
  • Lack of capability checks
Vulnerabilities
None known

Notify Bot for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Notify Bot for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
7
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
13
External Requests
1
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

30% escaped10 total outputs
Attack Surface
3 unprotected

Notify Bot for WooCommerce Attack Surface

Entry Points3
Unprotected3

AJAX Handlers 1

authwp_ajax_wootb_send_test_messageincludes\Initializer.php:59

REST API Routes 2

GET/wp-json/wootb/telegram/hookincludes\TelegramAPI.php:20
GET/wp-json/wootb/telegram/sendmsgsincludes\TelegramAPI.php:28
WordPress Hooks 16
actionadmin_noticesincludes\Initializer.php:26
actionplugins_loadedincludes\Initializer.php:31
filterplugin_action_links_notify-bot-woocommerce/notify-bot-woocommerce.phpincludes\Initializer.php:32
filterwoocommerce_product_variation_title_include_attributesincludes\Initializer.php:36
filterwoocommerce_is_attribute_in_product_nameincludes\Initializer.php:37
actionbefore_woocommerce_initincludes\Initializer.php:38
filterwoocommerce_get_settings_pagesincludes\Initializer.php:60
actionadmin_enqueue_scriptsincludes\Initializer.php:61
actionwoocommerce_update_orderincludes\Initializer.php:62
actionwoocommerce_new_orderincludes\Initializer.php:63
actionwoocommerce_checkout_order_processedincludes\Initializer.php:65
actionwoocommerce_order_status_changedincludes\Initializer.php:67
actionadmin_action_remove_wootb_userincludes\Initializer.php:69
filtercron_schedulesincludes\Initializer.php:71
actionwootb_queue_eventincludes\Initializer.php:72
actionrest_api_initincludes\TelegramAPI.php:12

Scheduled Events 1

wootb_queue_event
Maintenance & Trust

Notify Bot for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedDec 3, 2025
PHP min version7.4
Downloads3K

Community Trust

Rating100/100
Number of ratings2
Active installs100
Developer Profile

Notify Bot for WooCommerce Developer Profile

Ali Javaheri

1 plugin · 100 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Notify Bot for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/notify-bot-woocommerce/assets/css/admin.css/wp-content/plugins/notify-bot-woocommerce/assets/js/admin.js
Script Paths
/wp-content/plugins/notify-bot-woocommerce/assets/js/admin.js
Version Parameters
notify-bot-woocommerce/assets/css/admin.css?ver=notify-bot-woocommerce/assets/js/admin.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- START Notify Bot for WooCommerce Settings --><!-- END Notify Bot for WooCommerce Settings --><!-- START Notify Bot for WooCommerce User List --><!-- END Notify Bot for WooCommerce User List -->
Data Attributes
data-wootb-ajax-url
JS Globals
wootb_admin_params
REST Endpoints
/wp-json/wootb/v1/settings/wp-json/wootb/v1/users/wp-json/wootb/v1/test-message/wp-json/wootb/v1/user
FAQ

Frequently Asked Questions about Notify Bot for WooCommerce