SalesBuddy – Sales Pop Notifications Security & Risk Analysis

wordpress.org/plugins/salesbuddy-sales-pop-notifications

WooCommerce Sales Notification – Boost Conversions with Real-Time Order Alerts

0 active installs v1.0.2 PHP 7.4+ WP 5.0+ Updated Apr 6, 2025
pop-up-notificationsales-notification
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is SalesBuddy – Sales Pop Notifications Safe to Use in 2026?

Generally Safe

Score 92/100

SalesBuddy – Sales Pop Notifications has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The security posture of the 'salesbuddy-sales-pop-notifications' v1.0.2 plugin appears to be strong based on the provided static analysis. The absence of dangerous functions, SQL queries without prepared statements, unescaped output, file operations, and external HTTP requests are all positive indicators. Furthermore, the lack of recorded vulnerabilities in its history suggests a commitment to security or a lack of past exploitable issues. The attack surface is zero, meaning there are no publicly accessible entry points like AJAX handlers, REST API routes, or shortcodes that could be immediately exploited. Taint analysis also shows no unsanitized flows, reinforcing the idea of robust input handling.

However, the complete absence of capability checks and nonce checks is a significant concern, especially if this plugin were to introduce any functionality in the future that interacts with user actions or data. While the current version reports no direct vulnerabilities, this lack of basic security checks means that any future introduction of an attack vector without proper authorization and verification mechanisms would immediately create a high-risk scenario. The plugin's current state is secure due to its apparent lack of functionality or complex interaction points, but it relies heavily on this absence rather than proactive security measures for protection.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

SalesBuddy – Sales Pop Notifications Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

SalesBuddy – Sales Pop Notifications Release Timeline

v1.0.1
Code Analysis
Analyzed Mar 17, 2026

SalesBuddy – Sales Pop Notifications Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
37 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped37 total outputs
Attack Surface

SalesBuddy – Sales Pop Notifications Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actioninitincludes\class-sbsp-notification.php:53
actionadmin_initincludes\class-sbsp-notification.php:56
actionadmin_enqueue_scriptsincludes\class-sbsp-notification.php:59
actionwp_enqueue_scriptsincludes\class-sbsp-notification.php:62
actionwp_enqueue_scriptsincludes\class-sbsp-notification.php:65
actionadmin_menuincludes\class-sbsp-notification.php:68
actionadmin_noticesincludes\class-sbsp-notification.php:71
Maintenance & Trust

SalesBuddy – Sales Pop Notifications Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedApr 6, 2025
PHP min version7.4
Downloads335

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

SalesBuddy – Sales Pop Notifications Developer Profile

AcmeeDesign

3 plugins · 330 total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SalesBuddy – Sales Pop Notifications

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/salesbuddy-sales-pop-notifications/assets/css/toastr.min.css/wp-content/plugins/salesbuddy-sales-pop-notifications/assets/js/toastr.min.js/wp-content/plugins/salesbuddy-sales-pop-notifications/assets/css/animate.min.css/wp-content/plugins/salesbuddy-sales-pop-notifications/assets/css/backend.css/wp-content/plugins/salesbuddy-sales-pop-notifications/assets/js/sbsp-backend.js/wp-content/plugins/salesbuddy-sales-pop-notifications/assets/css/frontend.css/wp-content/plugins/salesbuddy-sales-pop-notifications/assets/js/sbsp-frontend.js
Script Paths
/wp-content/plugins/salesbuddy-sales-pop-notifications/assets/js/toastr.min.js/wp-content/plugins/salesbuddy-sales-pop-notifications/assets/js/sbsp-backend.js/wp-content/plugins/salesbuddy-sales-pop-notifications/assets/js/sbsp-frontend.js
Version Parameters
salesbuddy-sales-pop-notifications/assets/css/toastr.min.css?ver=salesbuddy-sales-pop-notifications/assets/js/toastr.min.js?ver=salesbuddy-sales-pop-notifications/assets/css/animate.min.css?ver=salesbuddy-sales-pop-notifications/assets/css/backend.css?ver=salesbuddy-sales-pop-notifications/assets/js/sbsp-backend.js?ver=salesbuddy-sales-pop-notifications/assets/css/frontend.css?ver=salesbuddy-sales-pop-notifications/assets/js/sbsp-frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
sbsp-toast-containersbsp-toastanimate__animatedsbsp-animation-class
HTML Comments
<!-- Salesbuddy Sales Pop Notification --><!-- Toastr Settings --><!-- Animated CSS Classes --><!-- Frontend CSS -->+1 more
Data Attributes
data-toast-positiondata-toast-animationdata-toast-timeoutdata-toast-close-buttondata-toast-progress-bar
JS Globals
sbsp_localize_datashow_sbsp_notification
FAQ

Frequently Asked Questions about SalesBuddy – Sales Pop Notifications