Product Notices for WooCommerce Security & Risk Analysis

wordpress.org/plugins/product-notices-for-woocommerce

Make the best of product announcements, promos, discounts, alerts, etc. on your eCommerce site with this one of its kind WooCommerce extension.

900 active installs v1.3.4 PHP 7.2+ WP 5.2+ Updated May 8, 2025
alertnoticesnotificationpromowoocommerce
79
B · Generally Safe
CVEs total1
Unpatched1
Last CVEApr 1, 2025
Safety Verdict

Is Product Notices for WooCommerce Safe to Use in 2026?

Mostly Safe

Score 79/100

Product Notices for WooCommerce is generally safe to use. 1 past CVE were resolved. Keep it updated.

1 known CVE 1 unpatched Last CVE: Apr 1, 2025Updated 11mo ago
Risk Assessment

The "product-notices-for-woocommerce" plugin, version 1.3.4, exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries, avoiding file operations and external HTTP requests, and having a high percentage of properly escaped output. The absence of critical or high-severity taint flows is also encouraging. However, significant concerns arise from the attack surface and the plugin's vulnerability history.

The plugin presents a total of two entry points, with one AJAX handler lacking authentication checks, which is a direct pathway for potential unauthorized actions. While the code analysis shows no dangerous functions, the unprotected AJAX handler could be exploited if an attacker can trigger it. The vulnerability history reveals a known medium-severity CVE that remains unpatched, indicating a persistent risk that has not been addressed by the developers. The prevalence of Cross-Site Request Forgery (CSRF) in its past vulnerabilities further suggests a need for robust nonce and capability checks on all user-facing actions.

In conclusion, while the plugin has foundational security strengths like secure SQL handling and output escaping, the unprotected AJAX endpoint and the unpatched medium-severity vulnerability introduce tangible risks. The developer should prioritize addressing the existing CVE and implementing proper authentication on all AJAX handlers to improve the overall security. The current score reflects these strengths alongside critical areas for improvement.

Key Concerns

  • Unpatched CVE (Medium Severity)
  • Unprotected AJAX handler
Vulnerabilities
1

Product Notices for WooCommerce Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-31807medium · 4.3Cross-Site Request Forgery (CSRF)

Product Notices for WooCommerce <= 1.3.3 - Cross-Site Request Forgery

Apr 1, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Product Notices for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
14
103 escaped
Nonce Checks
9
Capability Checks
5
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

88% escaped117 total outputs
Attack Surface
1 unprotected

Product Notices for WooCommerce Attack Surface

Entry Points2
Unprotected1

AJAX Handlers 1

authwp_ajax_update_notice_statusincludes\admin\class-crwcpn-admin-post-types.php:36

Shortcodes 1

[crwcpn-notice] includes\functions\core.php:448
WordPress Hooks 21
actioninitincludes\admin\class-crwcpn-admin-post-types.php:27
filterpost_updated_messagesincludes\admin\class-crwcpn-admin-post-types.php:29
filterbulk_post_updated_messagesincludes\admin\class-crwcpn-admin-post-types.php:30
filtermanage_product-notices-cpt_posts_columnsincludes\admin\class-crwcpn-admin-post-types.php:32
actionmanage_product-notices-cpt_posts_custom_columnincludes\admin\class-crwcpn-admin-post-types.php:33
actionadmin_enqueue_scriptsincludes\admin\class-crwcpn-admin-post-types.php:35
filterwoocommerce_settings_tabs_arrayincludes\admin\class-crwcpn-admin.php:31
actionadmin_enqueue_scriptsincludes\admin\class-crwcpn-admin.php:40
actionadd_meta_boxesincludes\admin\class-crwcpn-custom-fields.php:25
actionsave_postincludes\admin\class-crwcpn-custom-fields.php:27
actionadmin_enqueue_scriptsincludes\admin\class-crwcpn-custom-fields.php:30
actionedit_form_after_editorincludes\admin\class-crwcpn-notice-meta-boxes.php:25
actionsave_postincludes\admin\class-crwcpn-notice-meta-boxes.php:27
actionadmin_enqueue_scriptsincludes\admin\class-crwcpn-notice-meta-boxes.php:30
actionadmin_initincludes\class-crwcpn-settings-sanitization.php:287
actionwoocommerce_single_product_summaryincludes\functions\core.php:57
actionwoocommerce_single_product_summaryincludes\functions\core.php:181
actionwoocommerce_single_product_summaryincludes\functions\core.php:276
actionbefore_woocommerce_initproduct-notices-woocommerce.php:28
actionadmin_noticesproduct-notices-woocommerce.php:92
actionwp_enqueue_scriptsproduct-notices-woocommerce.php:102
Maintenance & Trust

Product Notices for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 8, 2025
PHP min version7.2
Downloads9K

Community Trust

Rating100/100
Number of ratings7
Active installs900
Developer Profile

Product Notices for WooCommerce Developer Profile

CloudRedux

2 plugins · 1K total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Product Notices for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/product-notices-for-woocommerce/assets/css/frontend/global.css
Version Parameters
product-notices-for-woocommerce/assets/css/frontend/global.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Product Notices for WooCommerce