
SalesPulse – Social Proof & FOMO Notifications Security & Risk Analysis
wordpress.org/plugins/salespulseBoost conversions with real-time social proof & FOMO popups. Show purchases, signups, reviews, visitor counts & announcement bars.
Is SalesPulse – Social Proof & FOMO Notifications Safe to Use in 2026?
Generally Safe
Score 100/100SalesPulse – Social Proof & FOMO Notifications has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The salespulse v1.0.1 plugin exhibits a concerning security posture primarily due to a large attack surface with a significant number of unprotected entry points. While the code signals are generally positive, with no dangerous functions, proper output escaping, and no file operations or external HTTP requests, the sheer volume of AJAX handlers and REST API routes lacking authorization checks presents a substantial risk. These unprotected endpoints could allow unauthenticated users to trigger sensitive actions or expose information, depending on their functionality.
The taint analysis, while limited in scope with only two flows analyzed, did identify one flow with an unsanitized path. This is a critical finding that, although not classified as high severity, indicates a potential for path traversal vulnerabilities if the flow's inputs are user-controlled and not properly validated. The lack of any recorded vulnerability history is a positive sign, suggesting the plugin has not been a target or has been developed with a reasonable degree of security awareness. However, this should not overshadow the immediate risks identified in the static analysis.
In conclusion, while the plugin demonstrates good practices in areas like output escaping and the absence of dangerous functions, the extensive number of unprotected AJAX handlers and REST API routes, coupled with a single unsanitized path flow, creates significant security weaknesses. These issues require immediate attention to harden the plugin's defenses against potential exploitation.
Key Concerns
- Unprotected AJAX handlers
- Unprotected REST API routes
- Flow with unsanitized path
SalesPulse – Social Proof & FOMO Notifications Security Vulnerabilities
SalesPulse – Social Proof & FOMO Notifications Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
SalesPulse – Social Proof & FOMO Notifications Attack Surface
AJAX Handlers 10
REST API Routes 8
Shortcodes 1
WordPress Hooks 13
Maintenance & Trust
SalesPulse – Social Proof & FOMO Notifications Maintenance & Trust
Maintenance Signals
Community Trust
SalesPulse – Social Proof & FOMO Notifications Alternatives
Sales Push Notification
sales-push-notification
Boost conversions with real-time sales notifications that build trust and create FOMO. Customizable, WooCommerce-compatible, and mobile-friendly.
Social Proof for WooCommerce
social-proof-for-woocommerce
Motivate your customers to buy from your online store. Show them social proof that other people are already buying from your store.
Fomo for WooCommerce
fomo
Fomo displays recent orders on your WooCommerce storefront.
NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar
notificationx
Want to boost business trust & conversions? 97% of visitors hesitate to buy because of credibility. Instantly succeed with WooCommerce Sales Alert!
FOMO & Social Proof Notifications by TrustPulse – Best WordPress FOMO Plugin
trustpulse-api
TrustPulse is a FOMO social proof plugin that leverages the power of social proof to instantly boost site conversions by up to 15%!
SalesPulse – Social Proof & FOMO Notifications Developer Profile
2 plugins · 0 total installs
How We Detect SalesPulse – Social Proof & FOMO Notifications
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/salespulse/assets/fonts/fonts.css/wp-content/plugins/salespulse/admin/css/admin.css/wp-content/plugins/salespulse/admin/js/admin.js/wp-content/plugins/salespulse/admin/js/admin.jssalespulse/assets/fonts/fonts.css?ver=salespulse/admin/css/admin.css?ver=salespulse/admin/js/admin.js?ver=HTML / DOM Fingerprints
salespulse-admin-wrappersalespulse-logosp-admin-notifications-tablesp-notification-rowsp-notification-titlesp-notification-statussp-notification-actionssp-notification-edit-link+25 more<!-- SalesPulse Admin Page --><!-- Main wrapper --><!-- Main content area --><!-- Notification table -->+10 moredata-notification-iddata-actiondata-template-iddata-toggledata-toggle-groupdata-type-requirementsalespulseAdmin/salespulse/v1/notifications/salespulse/v1/notifications/(?P<id>\d+)