
Proof Factor – Social Proof Notifications Security & Risk Analysis
wordpress.org/plugins/proof-factor-social-proof-notificationsProof Factor displays recent user sign ups!
Is Proof Factor – Social Proof Notifications Safe to Use in 2026?
Use With Caution
Score 63/100Proof Factor – Social Proof Notifications has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The plugin 'proof-factor-social-proof-notifications' v1.0.5 exhibits a mixed security posture. While the static analysis shows a clean bill of health regarding attack surface, SQL queries using prepared statements, and a lack of critical taint flows, several concerning signals are present. The most significant concern is the presence of unpatched vulnerabilities, specifically a medium severity Cross-site Scripting (XSS) issue. The low percentage of properly escaped output (22%) is also a red flag, as it suggests potential for XSS vulnerabilities, especially when combined with the historical XSS vulnerability.
The vulnerability history, with one unpatched medium-severity XSS, strongly indicates a recurring weakness in input sanitization and output escaping. While the current static analysis did not detect any explicit XSS based on taint flows or unsanitized paths, this could be due to the limitations of static analysis or the specific nature of the vulnerability not being flagged by the tools used. The absence of nonce and capability checks on the identified entry points, though the number is zero, suggests a potential oversight if new entry points were to be introduced or if the identified entry points are not thoroughly reviewed.
In conclusion, the plugin demonstrates good practices in preventing direct SQL injection and limiting its attack surface through code design. However, the presence of an unpatched XSS vulnerability and poor output escaping practices create a significant risk. The historical pattern of XSS issues points to a need for more robust security auditing and development practices within the plugin. Users should be cautious and prioritize updating to a version that addresses the known CVE.
Key Concerns
- Unpatched medium severity CVE (XSS)
- Low percentage of properly escaped output
- Missing nonce checks on entry points
- Missing capability checks on entry points
Proof Factor – Social Proof Notifications Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Proof Factor – Social Proof Notifications <= 1.0.5 - Authenticated (Administrator+) Stored Cross-Site Scripting
Proof Factor – Social Proof Notifications Code Analysis
Output Escaping
Proof Factor – Social Proof Notifications Attack Surface
WordPress Hooks 10
Maintenance & Trust
Proof Factor – Social Proof Notifications Maintenance & Trust
Maintenance Signals
Community Trust
Proof Factor – Social Proof Notifications Alternatives
Proof Factor – Social Proof Notifications for WooCommerce
proof-factor-social-proof-notifications-for-woocommerce
Proof Factor displays recent orders and purchases on your WooCommerce storefront!
Nudgify Social Proof
nudgify
Increase your sign-ups and sales by up to 15% with real-time Social Proof and FOMO messages. Show customer reviews and recent activity in real-time.
Useinfluence
useinfluence
UseInfluence uses 'Social Proof Notifications' to give a conversion BOOST to your website's traffic. Our realtime notifications puts a …
Social Proof for WooCommerce
social-proof-for-woocommerce
Motivate your customers to buy from your online store. Show them social proof that other people are already buying from your store.
Social Proof Popups & Real-Time Notifications – Herd Effects
mwp-herd-effect
Boost conversions with real-time social proof popups and user activity notifications, encouraging visitor actions on your WordPress site.
Proof Factor – Social Proof Notifications Developer Profile
2 plugins · 180 total installs
How We Detect Proof Factor – Social Proof Notifications
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/proof-factor-social-proof-notifications/admin/css/proof-factor-wp-admin.css/wp-content/plugins/proof-factor-social-proof-notifications/admin/js/proof-factor-wp-admin.js/wp-content/plugins/proof-factor-social-proof-notifications/admin/js/proof-factor-wp-admin.jsproof-factor-wp-admin.css?ver=proof-factor-wp-admin.js?ver=HTML / DOM Fingerprints
ps-errordata-plugin-name="Proof_Factor_WP"data-plugin-version="1.0.5"