Sales Notifications for WooCommerce – Recent Sales Popup Security & Risk Analysis

wordpress.org/plugins/wc-live-sale-notifications

Sales Notifications for WooCommerce - Recent Sales Popup boosts sales by showing recent orders in a popup with customer and product details.

50 active installs v2.0.6 PHP 7.0+ WP 4.4.0+ Updated Apr 24, 2025
alertsboostrecent-orders-popupsaleswoocommerce-notifications
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Sales Notifications for WooCommerce – Recent Sales Popup Safe to Use in 2026?

Generally Safe

Score 100/100

Sales Notifications for WooCommerce – Recent Sales Popup has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The wc-live-sale-notifications v2.0.6 plugin exhibits a concerning security posture due to a significant attack surface exposed without authentication. With 3 AJAX handlers identified and all of them lacking authentication checks, there is a substantial risk of unauthorized actions being performed on a WordPress site. This is further exacerbated by a complete absence of nonce checks, which are a fundamental security mechanism for AJAX requests. While the plugin demonstrates good practices in other areas such as using prepared statements for SQL queries and a high percentage of properly escaped output, these strengths are overshadowed by the critical lack of authorization on its primary entry points.

The lack of vulnerability history is a positive indicator, suggesting the plugin has not been a target or has not had exploitable flaws publicly disclosed. However, this should not breed complacency, especially given the identified structural weaknesses. The presence of an outdated bundled library (Select2) is a minor concern, but the primary and most pressing issue remains the unprotected AJAX endpoints. Without proper authentication and authorization, malicious actors could potentially exploit these handlers to manipulate sale notifications or perform other unintended actions, leading to data integrity issues or unauthorized content modification.

Key Concerns

  • 3 unprotected AJAX handlers
  • 0 nonce checks on AJAX handlers
  • Bundled library (Select2) may be outdated
Vulnerabilities
None known

Sales Notifications for WooCommerce – Recent Sales Popup Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Sales Notifications for WooCommerce – Recent Sales Popup Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
25 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
5
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

93% escaped27 total outputs
Attack Surface
3 unprotected

Sales Notifications for WooCommerce – Recent Sales Popup Attack Surface

Entry Points3
Unprotected3

AJAX Handlers 3

authwp_ajax_xslsn_getPopupdataxslsn-includes\xslsn-frontendpopup.php:57
noprivwp_ajax_xslsn_getPopupdataxslsn-includes\xslsn-frontendpopup.php:59
authwp_ajax_xslsn_send_mailxslsn-includes\xslsn-options.php:130
WordPress Hooks 5
actionwp_enqueue_scriptsxslsn-includes\xslsn-frontendpopup.php:3
actionwp_footerxslsn-includes\xslsn-frontendpopup.php:54
actionadmin_enqueue_scriptsxslsn-includes\xslsn-options.php:6
actionadmin_menuxslsn-includes\xslsn-options.php:21
actionadmin_initxslsn-includes\xslsn-options.php:115
Maintenance & Trust

Sales Notifications for WooCommerce – Recent Sales Popup Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 24, 2025
PHP min version7.0
Downloads4K

Community Trust

Rating100/100
Number of ratings2
Active installs50
Developer Profile

Sales Notifications for WooCommerce – Recent Sales Popup Developer Profile

Xfinitysoft

9 plugins · 4K total installs

99
trust score
Avg Security Score
99/100
Avg Patch Time
6 days
View full developer profile
Detection Fingerprints

How We Detect Sales Notifications for WooCommerce – Recent Sales Popup

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wc-live-sale-notifications/xslsn-assets/xslsn-css/xslsn-style.css/wp-content/plugins/wc-live-sale-notifications/xslsn-assets/xslsn-js/xslsn-mainfrontend.js
Script Paths
https://maxcdn.bootstrapcdn.com/font-awesome/4.6.0/css/font-awesome.min.css

HTML / DOM Fingerprints

CSS Classes
xslsn-style1xslsn-position-leftxslsn-position-topright
HTML Comments
Adding the html content on the page for modal
Data Attributes
id="xslsn-plugindirpath"
JS Globals
xslsn_optionsdataxslsn_mainfrontend
FAQ

Frequently Asked Questions about Sales Notifications for WooCommerce – Recent Sales Popup