Push new order to social SW Security & Risk Analysis

wordpress.org/plugins/push-new-order-to-social-sw

Push new order to social SW

40 active installs v1.0.0 PHP 5.6+ WP 5.0+ Updated Feb 3, 2023
notificationwooccommerce-to-telegramwoocommercewoocommerce-social
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Push new order to social SW Safe to Use in 2026?

Generally Safe

Score 85/100

Push new order to social SW has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "push-new-order-to-social-sw" plugin, version 1.0.0, exhibits a strong security posture based on the provided static analysis. There are no identified entry points to the plugin without authentication, and all observed SQL queries utilize prepared statements, mitigating common injection vulnerabilities. Furthermore, all output is properly escaped, and there are no dangerous function calls or file operations. The absence of any known CVEs or past vulnerability history is also a positive indicator of robust security practices.

However, the analysis does highlight a couple of areas for potential concern. The plugin makes two external HTTP requests, and while the data doesn't indicate any immediate risk, the nature of these requests and the handling of their responses would require further investigation to ensure they don't introduce vulnerabilities like SSRF or information disclosure. Additionally, the complete absence of nonce checks and capability checks across all identified entry points, combined with a lack of explicit authorization checks (though no entry points without auth were found), suggests a potential for privilege escalation or unauthorized actions if any such entry points were to be discovered or introduced in future versions. While currently not exposed, this lack of explicit checks is a deviation from best practices for more complex plugins.

In conclusion, version 1.0.0 of this plugin appears to be secure for its current functionality, demonstrating excellent adherence to fundamental security principles like prepared statements and output escaping. The primary areas for improvement lie in the explicit verification of authorization and nonces on any communication channels, even those currently assessed as protected, and a thorough review of the external HTTP requests. The plugin's clean history is a significant strength, but vigilance regarding the absence of authorization checks remains important.

Key Concerns

  • No nonce checks implemented
  • No capability checks implemented
  • External HTTP requests without detail
Vulnerabilities
None known

Push new order to social SW Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Push new order to social SW Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
21 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

100% escaped21 total outputs
Attack Surface

Push new order to social SW Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_enqueue_scriptspush-order-notify-sw.php:41
actionadmin_menupush-order-notify-sw.php:42
actionadmin_initpush-order-notify-sw.php:43
actionwoocommerce_thankyoupush-order-notify-sw.php:44
Maintenance & Trust

Push new order to social SW Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedFeb 3, 2023
PHP min version5.6
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs40
Developer Profile

Push new order to social SW Developer Profile

sonwebtl

2 plugins · 940 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Push new order to social SW

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/push-new-order-to-social-sw/assets/style_ponsw.css

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Push new order to social SW