Social Notifications for WooCommerce Security & Risk Analysis

wordpress.org/plugins/social-notifications-for-woocommerce

Sends WhatsApp notifications to your clients for order status changes. You can also receive a WhatsApp message when a new order is received.

10 active installs v1.1.2 PHP + WP 3.8+ Updated Dec 22, 2022
e-commercewhatsappwhatsapp-gatewaywhatsapp-notificationswoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Social Notifications for WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Social Notifications for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The 'social-notifications-for-woocommerce' plugin v1.1.2 presents a mixed security posture. On the positive side, it demonstrates good practices regarding SQL query sanitization and output escaping, with 100% of SQL queries using prepared statements and 95% of outputs properly escaped. The absence of recorded vulnerabilities and CVEs in its history is also a strong indicator of a well-maintained codebase. However, significant security concerns arise from the plugin's attack surface. With two AJAX handlers identified, both lacking authentication checks, there's a clear risk of unauthorized actions being performed if these handlers can be triggered externally. The complete absence of nonce checks and capability checks further exacerbates this risk, making these AJAX endpoints vulnerable to cross-site request forgery (CSRF) and unauthorized privilege escalation respectively. The bundled TCPDF library v1.0.004 is also a point of concern, as older versions of libraries can often harbor exploitable vulnerabilities. In conclusion, while the plugin benefits from secure database interactions and output handling, the unprotected AJAX endpoints and outdated bundled library represent critical security weaknesses that require immediate attention.

Key Concerns

  • AJAX handlers without auth checks
  • Missing nonce checks
  • Missing capability checks
  • Bundled outdated library TCPDF v1.0.004
Vulnerabilities
None known

Social Notifications for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Social Notifications for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
141 escaped
Nonce Checks
0
Capability Checks
0
File Operations
30
External Requests
3
Bundled Libraries
1

Bundled Libraries

TCPDF1.0.004

Output Escaping

95% escaped148 total outputs
Attack Surface
2 unprotected

Social Notifications for WooCommerce Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_suwcwam_send_otpplugin-core.php:163
noprivwp_ajax_suwcwam_send_otpplugin-core.php:164
WordPress Hooks 12
filterwoocommerce_checkout_fieldsplugin-core.php:50
actionwoocommerce_after_checkout_billing_formplugin-core.php:70
actionwoocommerce_checkout_processplugin-core.php:71
actionwoocommerce_admin_order_data_after_shipping_addressplugin-core.php:188
actioninitplugin-core.php:195
actionadmin_menuplugin-core.php:210
filterwoocommerce_screen_idsplugin-core.php:221
actionadmin_initplugin-core.php:229
actionwoocommerce_new_orderplugin-core.php:236
actionwoocommerce_order_status_changedplugin-core.php:255
filterplugin_row_metasocial-notifications-for-woocommerce.php:33
actionadmin_noticessocial-notifications-for-woocommerce.php:48
Maintenance & Trust

Social Notifications for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedDec 22, 2022
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Social Notifications for WooCommerce Developer Profile

SkillsUp

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Social Notifications for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/social-notifications-for-woocommerce/css/style.css/wp-content/plugins/social-notifications-for-woocommerce/js/script.js
Script Paths
/wp-content/plugins/social-notifications-for-woocommerce/js/script.js
Version Parameters
social-notifications-for-woocommerce/css/style.css?ver=social-notifications-for-woocommerce/js/script.js?ver=

HTML / DOM Fingerprints

JS Globals
suwcwam_settingsSU_WC_WA_Message_APIsuwcwam_loggersuwcwam_plugin_file
FAQ

Frequently Asked Questions about Social Notifications for WooCommerce