
Track.LK Notification – WooCommerce Security & Risk Analysis
wordpress.org/plugins/track-lk-notification-for-woocommerceSend SMS to Sri Lankan mobile numbers when an order is placed, or on order status changes on WooCommerce. You need active application from track.
Is Track.LK Notification – WooCommerce Safe to Use in 2026?
Generally Safe
Score 85/100Track.LK Notification – WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'track-lk-notification-for-woocommerce' plugin version 1.4 exhibits a mixed security posture. On the positive side, the code demonstrates good practices regarding SQL queries, exclusively using prepared statements, and has a high rate of output escaping, indicating a general awareness of preventing cross-site scripting vulnerabilities. The absence of known CVEs and historical vulnerabilities is also a strong positive indicator, suggesting a relatively stable and well-maintained codebase.
However, significant concerns arise from the static analysis. The plugin has one AJAX handler that lacks any authentication checks, creating a direct entry point for unauthenticated users to potentially trigger plugin functionality. This, combined with the absence of nonce checks, significantly increases the risk of unauthorized actions or potential exploits. The presence of an external HTTP request, while not inherently dangerous, warrants attention in conjunction with the unprotected AJAX handler, as it could be leveraged in an attack chain.
In conclusion, while the plugin avoids common pitfalls like raw SQL and outdated libraries, the single unprotected AJAX endpoint is a critical weakness. The lack of historical vulnerabilities is reassuring, but this one identified security gap is substantial and could be exploited without proper mitigation. Developers should prioritize securing this entry point.
Key Concerns
- Unprotected AJAX handler without auth check
- No nonce checks on AJAX entry point
- External HTTP request without context
Track.LK Notification – WooCommerce Security Vulnerabilities
Track.LK Notification – WooCommerce Release Timeline
Track.LK Notification – WooCommerce Code Analysis
Output Escaping
Track.LK Notification – WooCommerce Attack Surface
AJAX Handlers 1
WordPress Hooks 11
Maintenance & Trust
Track.LK Notification – WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Track.LK Notification – WooCommerce Alternatives
KhudeBarta Order Notify
khudebarta-order-notify
Send SMS via KhudeBarta API and notify customers automatically when WooCommerce order statuses change.
افزونه پیامک حرفه ای فراز اس ام اس
farazsms
شما می توانید با استفاده از افزونه فراز اس ام اس، سایت خود را با ابزاری خودکار برای ارسال پیامک و ذخیره شماره در دفترچه تلفن، تقویت کنید.
Alpha SMS
alpha-sms
Connect your WordPress and WooCommerce store to Alpha SMS for OTP verification and order notifications in Bangladesh.
miniOrange OTP Verification and SMS Notification for WooCommerce
miniorange-sms-order-notification-otp-verification
OTP Verification via SMS, Email,or WhatsApp, and SMS Order Notifications, Vendor Notifications for WooCommerce.OTP Login and registration with Phone →
SMS for WooCommerce
wc-sms
Order SMS Notifications for Woocommerce
Track.LK Notification – WooCommerce Developer Profile
1 plugin · 0 total installs
How We Detect Track.LK Notification – WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/track-lk-notification-for-woocommerce/assets/css/jquery.toast.css/wp-content/plugins/track-lk-notification-for-woocommerce/assets/css/tracknotify-admin.css/wp-content/plugins/track-lk-notification-for-woocommerce/assets/js/jquery.toast.js/wp-content/plugins/track-lk-notification-for-woocommerce/assets/js/tracknotify-admin.js/wp-content/plugins/track-lk-notification-for-woocommerce/assets/js/jquery.toast.js/wp-content/plugins/track-lk-notification-for-woocommerce/assets/js/tracknotify-admin.jstracknotify_toasttracknotify_adminHTML / DOM Fingerprints
tracknotify_admin_paramstracknotify_admin_params