WaMate Confirm – Order Confirmation Security & Risk Analysis

wordpress.org/plugins/wamate-confirm

WaMate Confirm is a powerful plugin designed to streamline your order confirmation process

40 active installs v2.0.4 PHP 7.0+ WP 5.4+ Updated Mar 4, 2026
order-confirmationorder-managementwhatsapp-order-confirmationwoocommerce-orders
78
B · Generally Safe
CVEs total1
Unpatched1
Last CVEFeb 10, 2026
Download
Safety Verdict

Is WaMate Confirm – Order Confirmation Safe to Use in 2026?

Mostly Safe

Score 78/100

WaMate Confirm – Order Confirmation is generally safe to use. 1 past CVE were resolved. Keep it updated.

1 known CVE 1 unpatched Last CVE: Feb 10, 2026Updated 1mo ago
Risk Assessment

The wamate-confirm v2.0.4 plugin exhibits a mixed security posture. While it demonstrates strong adherence to secure coding practices such as 100% use of prepared statements for SQL queries and a high percentage of output escaping, several concerns warrant attention. The presence of external HTTP requests without further details on their handling is a potential area for risk. Furthermore, the taint analysis revealing three flows with unsanitized paths, despite not reaching critical or high severity, indicates a potential for subtle vulnerabilities if not thoroughly reviewed and handled by developers. The plugin's vulnerability history is a significant concern, with one known medium-severity CVE that remains unpatched. The historical pattern of 'Missing Authorization' vulnerabilities suggests a recurring issue in how the plugin handles user permissions, which could be exploited if not addressed comprehensively. In conclusion, while the plugin has strengths in its internal coding practices, the unpatched medium-severity vulnerability and past authorization issues present the most immediate and significant risks. The taint analysis results also highlight an area for developer diligence.

Key Concerns

  • Unpatched medium severity CVE
  • Taint flows with unsanitized paths
  • External HTTP requests found
Vulnerabilities
1

WaMate Confirm – Order Confirmation Security Vulnerabilities

CVEs by Year

1 CVE in 2026 · unpatched
2026
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2026-1833medium · 5.3Missing Authorization

WaMate Confirm <= 2.0.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Phone Number Blocking/Unblocking

Feb 10, 2026Unpatched
Code Analysis
Analyzed Mar 16, 2026

WaMate Confirm – Order Confirmation Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
13
53 escaped
Nonce Checks
7
Capability Checks
6
File Operations
0
External Requests
4
Bundled Libraries
0

Output Escaping

80% escaped66 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

3 flows3 with unsanitized paths
wamate_log_page (customnotification.php:672)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WaMate Confirm – Order Confirmation Attack Surface

Entry Points4
Unprotected0

AJAX Handlers 4

authwp_ajax_wamate_resend_messagecustomnotification.php:1004
authwp_ajax_wamate_get_analyticscustomnotification.php:1725
authwp_ajax_wamate_reset_analyticscustomnotification.php:1793
authwp_ajax_grab_numbers_actioncustomnotification.php:1808
WordPress Hooks 8
actionadmin_menucustomnotification.php:17
actionadmin_initcustomnotification.php:1023
actionwoocommerce_new_ordercustomnotification.php:1351
actionwoocommerce_checkout_order_processedcustomnotification.php:1354
actionwoocommerce_order_status_changedcustomnotification.php:1612
actionwoocommerce_before_checkout_processcustomnotification.php:1868
actionwp_footercustomnotification.php:1877
filterwoocommerce_checkout_posted_datacustomnotification.php:1900
Maintenance & Trust

WaMate Confirm – Order Confirmation Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 4, 2026
PHP min version7.0
Downloads2K

Community Trust

Rating50/100
Number of ratings2
Active installs40
Developer Profile

WaMate Confirm – Order Confirmation Developer Profile

sm_rasmy

2 plugins · 60 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WaMate Confirm – Order Confirmation

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wamate-confirm/assets/css/style.css/wp-content/plugins/wamate-confirm/assets/js/script.js
Script Paths
/wp-content/plugins/wamate-confirm/assets/js/script.js
Version Parameters
wamate-confirm/assets/css/style.css?ver=wamate-confirm/assets/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
wamate-admin-wrapwamate-headerwamate-tabswamate-tabwamate-tab-contentcarbon-cardstatus-badgestatus-online+4 more
HTML Comments
<!-- Add WaMate top-level menu and subpages --><!-- Settings page content --><!-- Check user capabilities --><!-- Verify nonce for form submission -->+1 more
Data Attributes
data-wamate-nonce
JS Globals
wamate_admin_obj
Shortcode Output
[wamate_shortcode_example]
FAQ

Frequently Asked Questions about WaMate Confirm – Order Confirmation