Ultimate Notification Sender for WooCommerce Security & Risk Analysis

wordpress.org/plugins/wc-ultimate-notification-sender

Receive real-time notifications on Telegram for new orders in your WooCommerce store.

10 active installs v1.0.1 PHP + WP 5.8+ Updated Oct 28, 2024
telegram-bot-notificationtelegram-with-woocommercetelegram-wordpresswoocommerce-notification
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Ultimate Notification Sender for WooCommerce Safe to Use in 2026?

Generally Safe

Score 92/100

Ultimate Notification Sender for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The static analysis of wc-ultimate-notification-sender v1.0.1 reveals a plugin with a seemingly robust security posture based on the provided data. There are no identified dangerous functions, SQL queries are exclusively using prepared statements, and all output is properly escaped. The plugin also avoids file operations and external HTTP requests, which are common vectors for vulnerabilities.

However, there are several concerning signals. The complete absence of nonce checks and capability checks across all entry points (even though the attack surface is reported as zero) is a significant oversight. This means that if any entry points were to be introduced or discovered, they would be entirely unprotected against CSRF and unauthorized access. While taint analysis reported no issues, this could be due to the limited scope of the analysis or the lack of exploitable flows given the current entry points.

Given the zero known CVEs and the absence of any recorded vulnerabilities, the plugin appears to have a clean history. This suggests either diligent development practices or a lack of targeted attacks. Nevertheless, the critical lack of authentication and authorization checks on potential entry points is a fundamental security weakness that cannot be ignored. The plugin demonstrates good practices in core code security like SQL and output handling, but its overall security is compromised by the potential for unauthorized actions if any attack surface is ever exposed.

Key Concerns

  • No nonce checks on potential entry points
  • No capability checks on potential entry points
  • Single external HTTP request
Vulnerabilities
None known

Ultimate Notification Sender for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Ultimate Notification Sender for WooCommerce Release Timeline

v1.0.2
v1.0.1Current
Code Analysis
Analyzed Apr 16, 2026

Ultimate Notification Sender for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
11 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped11 total outputs
Attack Surface

Ultimate Notification Sender for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionadmin_menuadmin/ultimate-woo-admin-page.php:10
actionadmin_initadmin/ultimate-woo-admin-page.php:13
actionwoocommerce_new_orderinc/unsfw-new-order-notification.php:8
actionwoocommerce_order_status_cancelledinc/unsfw-order-cancelled-notification.php:8
actionwoocommerce_order_status_completedinc/unsfw-order-completed-notification.php:8
actionwoocommerce_order_status_pendinginc/unsfw-order-pending-notification.php:8
actionwoocommerce_order_status_processinginc/unsfw-order-processing-notification.php:8
actionwoocommerce_order_status_refundedinc/unsfw-order-refunded-notification.php:8
actionplugins_loadedultimate-notification-sender-for-woocommerce.php:28
Maintenance & Trust

Ultimate Notification Sender for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedOct 28, 2024
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Ultimate Notification Sender for WooCommerce Developer Profile

Masum Billah

3 plugins · 10 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Ultimate Notification Sender for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wc-ultimate-notification-sender/admin/ultimate-woo-admin-page.php/wp-content/plugins/wc-ultimate-notification-sender/inc/unsfw-order-pending-notification.php/wp-content/plugins/wc-ultimate-notification-sender/inc/unsfw-new-order-notification.php/wp-content/plugins/wc-ultimate-notification-sender/inc/unsfw-order-processing-notification.php/wp-content/plugins/wc-ultimate-notification-sender/inc/unsfw-order-completed-notification.php/wp-content/plugins/wc-ultimate-notification-sender/inc/unsfw-order-cancelled-notification.php/wp-content/plugins/wc-ultimate-notification-sender/inc/unsfw-order-refunded-notification.php

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Ultimate Notification Sender for WooCommerce