
ShopNotify – Personalized Cart Recovery for WooCommerce Security & Risk Analysis
wordpress.org/plugins/shopnotifyTrack abandoned carts for logged-in and guest users in WooCommerce, send automated WhatsApp reminders, and gain insights into cart recovery and abando …
Is ShopNotify – Personalized Cart Recovery for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100ShopNotify – Personalized Cart Recovery for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "shopnotify" plugin, version 1.0.0, exhibits a generally good security posture with strong practices in several key areas. The extensive use of prepared statements for SQL queries (95%) and proper output escaping (96%) significantly mitigates common web vulnerabilities like SQL injection and XSS. The absence of bundled libraries and file operations further reduces potential attack vectors. The plugin also demonstrates awareness of security by implementing a sufficient number of nonce checks for its entry points.
However, concerns arise from the taint analysis, which identified two flows with unsanitized paths at a high severity. While these are not explicitly labeled as exploitable vulnerabilities in the static analysis, they represent potential weaknesses that could be leveraged by an attacker if not properly handled. Furthermore, the lack of capability checks on any of the entry points (AJAX handlers) is a significant omission. This means that potentially sensitive actions could be performed by any logged-in user, regardless of their role or permissions, increasing the risk of unauthorized access or modification.
The plugin's vulnerability history is clean, with zero recorded CVEs. This is a positive indicator, suggesting that the code, as it stands, has likely not been subject to publicly disclosed exploits. However, the absence of past vulnerabilities should not be confused with guaranteed future security, especially given the identified taint flows. The overall conclusion is that "shopnotify" v1.0.0 has a solid foundation in terms of common security practices but requires immediate attention to address the unsanitized paths and implement robust capability checks to ensure secure access control.
Key Concerns
- High severity unsanitized paths in taint flows
- No capability checks on AJAX handlers
ShopNotify – Personalized Cart Recovery for WooCommerce Security Vulnerabilities
ShopNotify – Personalized Cart Recovery for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
ShopNotify – Personalized Cart Recovery for WooCommerce Attack Surface
AJAX Handlers 3
WordPress Hooks 25
Scheduled Events 2
Maintenance & Trust
ShopNotify – Personalized Cart Recovery for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
ShopNotify – Personalized Cart Recovery for WooCommerce Alternatives
CartResQ – Recover Abandoned Carts for WooCommerce
cartresq
Abandoned cart tracking for WooCommerce. Monitor, analyze, and recover lost sales with real-time detection and analytics.
ShopMetrics for WooCommerce
shopmetrics
Easy and Smart Analytics Dashboard with Automatic Cart Recovery for WooCommerce stores.
Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools
woocommerce-jetpack
Supercharge WooCommerce with FREE Abandoned Cart Recovery, Product Variation Swatches, PDF Invoices & 100+ tools. Boost sales & save time.
Abandoned Cart Recovery for WooCommerce
woo-abandoned-cart-recovery
A simple, effective solution to capture abandoned carts and auto-send reminders. Track logs and generate reports on carts, emails, and more
Cart Lift – Abandoned Cart Recovery for WooCommerce and EDD
cart-lift
Track abandoned carts and send automated, customizable abandoned cart recovery emails. Get more leads, reduce cart abandonment, and increase revenue.
ShopNotify – Personalized Cart Recovery for WooCommerce Developer Profile
7 plugins · 15K total installs
How We Detect ShopNotify – Personalized Cart Recovery for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shopnotify/admin/assets/js/shopnotify-admin.js/wp-content/plugins/shopnotify/admin/assets/css/shopnotify-admin.cssshopnotify/admin/assets/js/shopnotify-admin.js?ver=shopnotify/admin/assets/css/shopnotify-admin.css?ver=HTML / DOM Fingerprints
shpn-tab-contentshpn-settingsshpn-tab-panelshpn-documentation-wrappershpn-itemshpn-buttonshpn-button-primaryshpn-insights-container+2 moredata-urlshopnotify_vars/wp-json/shopnotify/v1/cart