
Notify Odoo Security & Risk Analysis
wordpress.org/plugins/notify-odooNotifies Odoo about a new order on WooCommerce.
Is Notify Odoo Safe to Use in 2026?
Generally Safe
Score 99/100Notify Odoo has a strong security track record. Known vulnerabilities have been patched promptly.
The "notify-odoo" v1.0.1 plugin exhibits significant security concerns, primarily stemming from its unprotected AJAX endpoint and a history of medium-severity vulnerabilities. While the plugin has no reported unpatched CVEs, the presence of a past medium vulnerability, specifically a Cross-Site Request Forgery (CSRF), suggests potential weaknesses in its security implementation. The static analysis reveals a concerning lack of authorization checks on its single AJAX handler, creating a clear attack vector. Furthermore, the low percentage of properly escaped output (15%) indicates a risk of Cross-Site Scripting (XSS) vulnerabilities, as data might be rendered directly into the browser without proper sanitization.
The taint analysis shows all flows with unsanitized paths, although they are not classified as critical or high severity. This is still a concern and, combined with the file operations and external HTTP requests, could lead to unintended consequences if these flows are manipulated. The absence of nonce checks and capability checks on its entry points further exacerbates the risks associated with the unprotected AJAX handler. The plugin's vulnerability history, while currently clear of unpatched issues, points to a pattern where security oversights have occurred, necessitating vigilant monitoring and patching.
In conclusion, "notify-odoo" v1.0.1 presents a moderate to high security risk due to its exposed attack surface and weak output escaping. While no critical or unpatched vulnerabilities are currently known, the existing data strongly suggests that the plugin is not following robust security best practices. The unprotected AJAX handler and potential for XSS vulnerabilities are the most immediate concerns. Developers should prioritize addressing these issues to improve the plugin's overall security posture.
Key Concerns
- Unprotected AJAX handler
- Low percentage of properly escaped output
- Flows with unsanitized paths
- No nonce checks
- No capability checks
- Medium severity vulnerability history
Notify Odoo Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Notify Odoo <= 1.0.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Notify Odoo Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Notify Odoo Attack Surface
AJAX Handlers 1
WordPress Hooks 7
Maintenance & Trust
Notify Odoo Maintenance & Trust
Maintenance Signals
Community Trust
Notify Odoo Alternatives
Advanced Order Export For WooCommerce
woo-order-export-lite
Export WooCommerce orders to Excel, CSV, XML, JSON, PDF and HTML. Best free order export plugin for WooCommerce.
Order Export & Order Import for WooCommerce
order-import-export-for-woocommerce
The best order export import plugin for WooCommerce. Easily import and export WooCommerce orders and WooCommerce coupons using CSV.
Export All Posts, Products, Orders, Refunds & Users
wp-ultimate-exporter
Export any WordPress website including WooCommerce data seamlessly with our powerful export plugin. Save records as CSV, XML, or Excel file for secure …
Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers
woocommerce-exporter
Export WooCommerce products, orders, customers, categories, tags, subscriptions & more into formatted files like CSV, XML, Excel 2007, XLS, XLSX.
Order Export for WooCommerce
order-export-and-more-for-woocommerce
Export WooCommerce orders & export products with advanced filtering. Supports CSV & all Excel formats.
Notify Odoo Developer Profile
14 plugins · 6K total installs
How We Detect Notify Odoo
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/notify-odoo/view/adminhtml/web/no/main.cssnotifyodoo_styleHTML / DOM Fingerprints
/wp-json/notifyodoo/v1/getNotifications