TP Price Drop Notifier for WooCommerce Security & Risk Analysis

wordpress.org/plugins/tp-price-drop-notifier-for-woocommerce

TP Price Drop Notifier for WooCommerce PRO is a very powerful extension for your woocommerce store, Give your customers a new option to track product …

10 active installs v1.0.3 PHP + WP 4.5+ Updated Nov 1, 2023
price-dropprice-trackproduct-price-dropwoocommerce-price-trackwoocommerce-product-price-drop
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is TP Price Drop Notifier for WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

TP Price Drop Notifier for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The tp-price-drop-notifier-for-woocommerce plugin exhibits a mixed security posture. While it demonstrates good practices in SQL query preparation (71% prepared) and output escaping (89% properly escaped), and has no recorded historical vulnerabilities, several concerning areas require attention. The presence of two AJAX handlers without authentication checks creates a significant attack surface. Furthermore, the taint analysis reveals two flows with unsanitized paths classified as high severity, indicating a potential for malicious data to be processed without proper validation or sanitization. These unsanitized flows, combined with the unprotected AJAX endpoints, present a notable risk that could lead to various security vulnerabilities if exploited.

The lack of recorded CVEs is a positive indicator of past security awareness or a less targeted plugin. However, this does not negate the immediate risks identified in the static analysis. The plugin's strengths lie in its general adherence to secure coding practices for SQL and output handling. The primary weaknesses are the unprotected entry points and the critical taint flows, which, if exploited, could have significant security implications despite the absence of past public vulnerabilities. A balanced approach would involve addressing these immediate code-level risks while maintaining vigilance for future threats.

Key Concerns

  • Unprotected AJAX handlers
  • High severity unsanitized taint flows
  • Missing capability checks on AJAX
Vulnerabilities
None known

TP Price Drop Notifier for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

TP Price Drop Notifier for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
5 prepared
Unescaped Output
17
141 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

DataTables

SQL Query Safety

71% prepared7 total queries

Output Escaping

89% escaped158 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
save_price_drop_notifier (public\class-tp-price-drop-notifier-for-woocommerce-public.php:185)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

TP Price Drop Notifier for WooCommerce Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_save_price_drop_notifierincludes\class-tp-price-drop-notifier-for-woocommerce.php:197
noprivwp_ajax_save_price_drop_notifierincludes\class-tp-price-drop-notifier-for-woocommerce.php:198
WordPress Hooks 14
actionadmin_menuadmin\partials\tp-price-drop-notifier-for-woocommerce-admin-display.php:16
actionadmin_initadmin\partials\tp-price-drop-notifier-for-woocommerce-admin-display.php:26
actionplugins_loadedincludes\class-tp-price-drop-notifier-for-woocommerce.php:143
actionadmin_enqueue_scriptsincludes\class-tp-price-drop-notifier-for-woocommerce.php:158
actionadmin_enqueue_scriptsincludes\class-tp-price-drop-notifier-for-woocommerce.php:159
filterplugin_row_metaincludes\class-tp-price-drop-notifier-for-woocommerce.php:162
actionsave_postincludes\class-tp-price-drop-notifier-for-woocommerce.php:164
filtercron_schedulesincludes\class-tp-price-drop-notifier-for-woocommerce.php:167
actionwpincludes\class-tp-price-drop-notifier-for-woocommerce.php:168
actionwoocommerce_send_email_digestincludes\class-tp-price-drop-notifier-for-woocommerce.php:169
actionwp_enqueue_scriptsincludes\class-tp-price-drop-notifier-for-woocommerce.php:184
actionwp_enqueue_scriptsincludes\class-tp-price-drop-notifier-for-woocommerce.php:185
actionwoocommerce_before_add_to_cart_formincludes\class-tp-price-drop-notifier-for-woocommerce.php:193
actionwp_footerincludes\class-tp-price-drop-notifier-for-woocommerce.php:195

Scheduled Events 1

woocommerce_send_email_digest
Maintenance & Trust

TP Price Drop Notifier for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.3.8
Last updatedNov 1, 2023
PHP min version
Downloads1K

Community Trust

Rating60/100
Number of ratings2
Active installs10
Developer Profile

TP Price Drop Notifier for WooCommerce Developer Profile

Payment Plugins

65 plugins · 296K total installs

85
trust score
Avg Security Score
96/100
Avg Patch Time
88 days
View full developer profile
Detection Fingerprints

How We Detect TP Price Drop Notifier for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tp-price-drop-notifier-for-woocommerce/icons/css/fontello.css/wp-content/plugins/tp-price-drop-notifier-for-woocommerce/css/jquery.minicolors.css/wp-content/plugins/tp-price-drop-notifier-for-woocommerce/css/tp-price-drop-notifier-for-woocommerce-admin.css/wp-content/plugins/tp-price-drop-notifier-for-woocommerce/js/jquery.minicolors.min.js/wp-content/plugins/tp-price-drop-notifier-for-woocommerce/js/tp-price-drop-notifier-for-woocommerce-admin.js
Script Paths
/wp-content/plugins/tp-price-drop-notifier-for-woocommerce/js/jquery.minicolors.min.js/wp-content/plugins/tp-price-drop-notifier-for-woocommerce/js/tp-price-drop-notifier-for-woocommerce-admin.js
Version Parameters
tp-price-drop-notifier-for-woocommerce-icons?ver=minicolors?ver=tp-price-drop-notifier-for-woocommerce?ver=minicolors?ver=

HTML / DOM Fingerprints

CSS Classes
tpc_get_protpc_live_demo
Data Attributes
class="tpc_get_pro"class="tpc_live_demo"
JS Globals
TPPDN_PLUGIN_NAMETPPDN_PLUGIN_MENU_NAMETPPDN_PLUGIN_BASENAMETPPDN_PLUGIN_HOMETPPDN_PLUGIN_APITPPDN_PLUGIN_SLUG
FAQ

Frequently Asked Questions about TP Price Drop Notifier for WooCommerce