
SALERT – Fake Sales Notification WooCommerce Security & Risk Analysis
wordpress.org/plugins/salertDisplay beautiful popup sales notification on your website with just few clicks.
Is SALERT – Fake Sales Notification WooCommerce Safe to Use in 2026?
Generally Safe
Score 99/100SALERT – Fake Sales Notification WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'salert' plugin v1.3.0 exhibits a mixed security posture. While it demonstrates good practices by utilizing prepared statements for all SQL queries and not performing file operations or external HTTP requests, significant concerns arise from its attack surface and output escaping. Two out of three AJAX handlers lack authentication checks, presenting a direct pathway for unauthorized actions. Furthermore, a concerningly low 41% of output is properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities, especially when combined with the unprotected AJAX endpoints. The plugin's history of two medium-severity vulnerabilities, specifically XSS and Missing Authorization, directly aligns with the current code analysis findings, suggesting a recurring pattern of these weaknesses. Despite the absence of critical taint flows and dangerous functions in this static analysis, the combination of unprotected entry points and poor output sanitization, coupled with historical vulnerability trends, makes this version of the plugin moderately risky.
Key Concerns
- AJAX handlers without auth checks
- Low percentage of properly escaped output
- Medium severity XSS and Missing Authorization history
SALERT – Fake Sales Notification WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
SALERT <= 1.2.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting
SALERT <= 1.2.1 - Missing Authorization via salert_save_settings_with_ajax()
SALERT – Fake Sales Notification WooCommerce Release Timeline
SALERT – Fake Sales Notification WooCommerce Code Analysis
Output Escaping
SALERT – Fake Sales Notification WooCommerce Attack Surface
AJAX Handlers 3
WordPress Hooks 5
Maintenance & Trust
SALERT – Fake Sales Notification WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
SALERT – Fake Sales Notification WooCommerce Alternatives
PiWeb Live sales notification for WooCommerce
live-sales-notifications-for-woocommerce
Fake sales alert for WooCommerce or Live sales notification for WooCommerce. Boost sales by encouraging your visitors to buy when they see your live n …
NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar
notificationx
Want to boost business trust & conversions? 97% of visitors hesitate to buy because of credibility. Instantly succeed with WooCommerce Sales Alert!
Live Sales Notification (Recent Sales Popups)
sales-pop
Beautiful live sales popups to feed recent orders to visitors. Best social proof to motivate customers to purchase and build brand trust.
WP Live Social-Proof
wp-real-time-social-proof
The best animated, live, social-proof plugin for WooCommerce, Easy Digital Downloads or webinars and subscriptions to compel buyer action.
Elite Notification – Sales Popup, Social Proof, FOMO Notification for WooCommerce
elite-notification
ELITE-NOTIFICATION is the best FOMO, Sales Pop-up, Comment, Review & WooCommerce notification with social proof wordpress plugin.
SALERT – Fake Sales Notification WooCommerce Developer Profile
11 plugins · 17K total installs
How We Detect SALERT – Fake Sales Notification WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/salert/assets/frontend/css/style.css/wp-content/plugins/salert/assets/frontend/js/main.js/wp-content/plugins/salert/assets/backend/css/salert-admin.css/wp-content/plugins/salert/assets/backend/css/animate.css/wp-content/plugins/salert/assets/backend/css/sweetalert2.min.css/wp-content/plugins/salert/assets/backend/js/core.js/wp-content/plugins/salert/assets/backend/js/sweetalert2.min.js/wp-content/plugins/salert/assets/backend/js/custom.js+1 more/wp-content/plugins/salert/assets/frontend/js/main.js/wp-content/plugins/salert/assets/backend/js/core.js/wp-content/plugins/salert/assets/backend/js/sweetalert2.min.js/wp-content/plugins/salert/assets/backend/js/custom.js/wp-content/plugins/salert/assets/backend/js/salert-admin.jssalert/style.css?ver=salert-main-css?ver=animate-css?ver=salert-admin-css?ver=sweetalert2.min.css?ver=core.js?ver=sweetalert2.min.js?ver=custom.js?ver=salert-admin.js?ver=main.js?ver=HTML / DOM Fingerprints
sale_alert_wrapperpopup_positionpopup_boxpopup_templateanimatedclearfixid="salertWrapper"admin_settings/wp-json/salert_get_content