Proof Factor – Social Proof Notifications Security & Risk Analysis

wordpress.org/plugins/proof-factor-social-proof-notifications

Proof Factor displays recent user sign ups!

100 active installs v1.0.5 PHP 5.3+ WP 3.0.1+ Updated Mar 13, 2019
notificationspopupspurchasesrecent-salessocial-proof
63
C · Use Caution
CVEs total1
Unpatched1
Last CVESep 22, 2025
Download
Safety Verdict

Is Proof Factor – Social Proof Notifications Safe to Use in 2026?

Use With Caution

Score 63/100

Proof Factor – Social Proof Notifications has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Sep 22, 2025Updated 7yr ago
Risk Assessment

The plugin 'proof-factor-social-proof-notifications' v1.0.5 exhibits a mixed security posture. While the static analysis shows a clean bill of health regarding attack surface, SQL queries using prepared statements, and a lack of critical taint flows, several concerning signals are present. The most significant concern is the presence of unpatched vulnerabilities, specifically a medium severity Cross-site Scripting (XSS) issue. The low percentage of properly escaped output (22%) is also a red flag, as it suggests potential for XSS vulnerabilities, especially when combined with the historical XSS vulnerability.

The vulnerability history, with one unpatched medium-severity XSS, strongly indicates a recurring weakness in input sanitization and output escaping. While the current static analysis did not detect any explicit XSS based on taint flows or unsanitized paths, this could be due to the limitations of static analysis or the specific nature of the vulnerability not being flagged by the tools used. The absence of nonce and capability checks on the identified entry points, though the number is zero, suggests a potential oversight if new entry points were to be introduced or if the identified entry points are not thoroughly reviewed.

In conclusion, the plugin demonstrates good practices in preventing direct SQL injection and limiting its attack surface through code design. However, the presence of an unpatched XSS vulnerability and poor output escaping practices create a significant risk. The historical pattern of XSS issues points to a need for more robust security auditing and development practices within the plugin. Users should be cautious and prioritize updating to a version that addresses the known CVE.

Key Concerns

  • Unpatched medium severity CVE (XSS)
  • Low percentage of properly escaped output
  • Missing nonce checks on entry points
  • Missing capability checks on entry points
Vulnerabilities
1

Proof Factor – Social Proof Notifications Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-58658medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Proof Factor &#8211; Social Proof Notifications <= 1.0.5 - Authenticated (Administrator+) Stored Cross-Site Scripting

Sep 22, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Proof Factor – Social Proof Notifications Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
3
Bundled Libraries
0

Output Escaping

22% escaped9 total outputs
Attack Surface

Proof Factor – Social Proof Notifications Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionplugins_loadedincludes\class-proof-factor-wp.php:142
actionadmin_enqueue_scriptsincludes\class-proof-factor-wp.php:157
actionadmin_enqueue_scriptsincludes\class-proof-factor-wp.php:158
actionadmin_noticesincludes\class-proof-factor-wp.php:159
actionadmin_menuincludes\class-proof-factor-wp.php:162
actionadmin_initincludes\class-proof-factor-wp.php:168
actionadmin_initincludes\class-proof-factor-wp.php:169
actionwp_enqueue_scriptsincludes\class-proof-factor-wp.php:186
actionwp_enqueue_scriptsincludes\class-proof-factor-wp.php:187
actionwp_footerincludes\class-proof-factor-wp.php:188
Maintenance & Trust

Proof Factor – Social Proof Notifications Maintenance & Trust

Maintenance Signals

WordPress version tested5.1.22
Last updatedMar 13, 2019
PHP min version5.3
Downloads4K

Community Trust

Rating100/100
Number of ratings12
Active installs100
Developer Profile

Proof Factor – Social Proof Notifications Developer Profile

Proof Factor LLC

2 plugins · 180 total installs

76
trust score
Avg Security Score
74/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Proof Factor – Social Proof Notifications

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/proof-factor-social-proof-notifications/admin/css/proof-factor-wp-admin.css/wp-content/plugins/proof-factor-social-proof-notifications/admin/js/proof-factor-wp-admin.js
Script Paths
/wp-content/plugins/proof-factor-social-proof-notifications/admin/js/proof-factor-wp-admin.js
Version Parameters
proof-factor-wp-admin.css?ver=proof-factor-wp-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
ps-error
Data Attributes
data-plugin-name="Proof_Factor_WP"data-plugin-version="1.0.5"
FAQ

Frequently Asked Questions about Proof Factor – Social Proof Notifications