Nudgify Social Proof Security & Risk Analysis

wordpress.org/plugins/nudgify

Increase your sign-ups and sales by up to 15% with real-time Social Proof and FOMO messages. Show customer reviews and recent activity in real-time.

600 active installs v1.3.15 PHP + WP 4.6+ Updated Feb 23, 2026
fomonotificationsrecent-salessales-popsocial-proof
99
A · Safe
CVEs total1
Unpatched0
Last CVEApr 5, 2024
Safety Verdict

Is Nudgify Social Proof Safe to Use in 2026?

Generally Safe

Score 99/100

Nudgify Social Proof has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Apr 5, 2024Updated 1mo ago
Risk Assessment

The Nudgify v1.3.15 plugin exhibits a mixed security posture, with several strengths but also significant areas of concern that necessitate attention. On the positive side, the plugin demonstrates good practices regarding SQL query handling, utilizing prepared statements exclusively, and also shows a high percentage of properly escaped output. The absence of bundled libraries and file operations further reduces potential attack vectors. However, the plugin has a notable vulnerability in its attack surface, with all four identified AJAX handlers lacking proper authentication checks. This presents a direct and exploitable path for unauthorized actions if an attacker can trigger these AJAX calls. While there are no critical or high severity taint analysis findings, the lack of auth checks on AJAX endpoints is a critical oversight. The vulnerability history indicates one medium severity CVE related to Cross-Site Request Forgery (CSRF) which was recently patched, suggesting that the developers are responsive to security issues, but also that such vulnerabilities can exist. The primary risk stems from the unprotected AJAX endpoints, which, if exploited in conjunction with other potential weaknesses not immediately apparent in static analysis, could lead to significant security breaches.

Key Concerns

  • AJAX handlers without authentication checks
  • Recent medium severity CVE (CSRF)
Vulnerabilities
1

Nudgify Social Proof Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-31239medium · 4.3Cross-Site Request Forgery (CSRF)

Nudgify Social Proof, Sales Popup & FOMO <= 1.3.3 - Cross-Site Request Forgery via sync_orders_manually()

Apr 5, 2024 Patched in 1.3.4 (7d)
Code Analysis
Analyzed Mar 16, 2026

Nudgify Social Proof Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
105 escaped
Nonce Checks
2
Capability Checks
3
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

95% escaped111 total outputs
Attack Surface
4 unprotected

Nudgify Social Proof Attack Surface

Entry Points4
Unprotected4

AJAX Handlers 4

authwp_ajax_nudgify_apply_discountnudgify.php:152
authwp_ajax_nudgify_check_discountnudgify.php:153
noprivwp_ajax_nudgify_apply_discountnudgify.php:154
noprivwp_ajax_nudgify_check_discountnudgify.php:155
WordPress Hooks 11
actionplugins_loadednudgify.php:78
actionwp_headnudgify.php:97
actionadmin_initnudgify.php:99
actionadmin_menunudgify.php:100
actionwoocommerce_new_ordernudgify.php:143
actionwoocommerce_add_to_cartnudgify.php:144
actionwoocommerce_remove_cart_itemnudgify.php:145
actionwoocommerce_after_cart_item_quantity_updatenudgify.php:146
actionwoocommerce_checkout_order_processednudgify.php:148
actionwoocommerce_order_status_cancellednudgify.php:149
actionwoocommerce_order_status_refundednudgify.php:150
Maintenance & Trust

Nudgify Social Proof Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedFeb 23, 2026
PHP min version
Downloads26K

Community Trust

Rating100/100
Number of ratings5
Active installs600
Developer Profile

Nudgify Social Proof Developer Profile

Nudgify

1 plugin · 600 total installs

99
trust score
Avg Security Score
99/100
Avg Patch Time
7 days
View full developer profile
Detection Fingerprints

How We Detect Nudgify Social Proof

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/nudgify/assets/css/common.css/wp-content/plugins/nudgify/assets/css/admin.css/wp-content/plugins/nudgify/assets/js/common.js/wp-content/plugins/nudgify/assets/js/admin.js
Script Paths
/wp-content/plugins/nudgify/assets/js/common.js/wp-content/plugins/nudgify/assets/js/admin.js
Version Parameters
nudgify/assets/css/common.css?ver=nudgify/assets/css/admin.css?ver=nudgify/assets/js/common.js?ver=nudgify/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
nudgify-settings-page
HTML Comments
<!-- Nudgify pixel --><!-- Nudgify JS Settings -->
Data Attributes
data-nudgify-site-keydata-nudgify-user-iddata-nudgify-enableddata-nudgify-tracking-id
JS Globals
nudgify_settingsNudgify
REST Endpoints
/wp-json/nudgify/v1/settings
FAQ

Frequently Asked Questions about Nudgify Social Proof