WPFomo Security & Risk Analysis

wordpress.org/plugins/wpfomo

Fomo notification for WordPress.

700 active installs v1.1.0 PHP + WP 4.0+ Updated Aug 28, 2019
fomofomo-notificationnotifier
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WPFomo Safe to Use in 2026?

Generally Safe

Score 85/100

WPFomo has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The plugin "wpfomo" v1.1.0 exhibits a generally strong security posture based on the static analysis. The complete absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is commendable. The presence of nonce and capability checks on all identified entry points is a significant positive, indicating that the developers have implemented fundamental security measures to protect against common attacks like CSRF and unauthorized access. The lack of any recorded vulnerabilities in its history further bolsters this positive impression.

However, a significant concern arises from the output escaping. With 54% of outputs properly escaped, a substantial portion (46%) remains unescaped. This presents a risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected into the plugin's output, impacting users. While taint analysis reported zero flows, this might be due to the limited scope or complexity of the plugin's code, and the unescaped output is a direct indicator of potential XSS vectors. The attack surface, though small, is entirely reliant on the implemented capability checks for its protection, making the unescaped output the primary area of concern.

In conclusion, "wpfomo" v1.1.0 demonstrates good foundational security practices with robust input validation and access control. Its vulnerability-free history is a positive sign. The main weakness lies in the inconsistent output escaping, which requires immediate attention to mitigate potential XSS risks.

Key Concerns

  • 46% of outputs are not properly escaped
Vulnerabilities
None known

WPFomo Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WPFomo Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
16
19 escaped
Nonce Checks
1
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

54% escaped35 total outputs
Attack Surface

WPFomo Attack Surface

Entry Points4
Unprotected0

AJAX Handlers 1

authwp_ajax_Nx_Installer_installerincludes\notificationx-installer.php:36

Shortcodes 3

[primary_text] public\partials\wpfomo-public-display.php:40
[link_text] public\partials\wpfomo-public-display.php:50
[secondary_text] public\partials\wpfomo-public-display.php:62
WordPress Hooks 12
actionplugins_loadedincludes\class-wpfomo.php:146
actionadmin_enqueue_scriptsincludes\class-wpfomo.php:161
actionadmin_enqueue_scriptsincludes\class-wpfomo.php:162
actionadmin_menuincludes\class-wpfomo.php:163
actionadmin_initincludes\class-wpfomo.php:164
actionwp_enqueue_scriptsincludes\class-wpfomo.php:179
actionwp_enqueue_scriptsincludes\class-wpfomo.php:180
actioninitincludes\notificationx-installer.php:16
actionadmin_noticesincludes\notificationx-installer.php:34
actionwp_footerpublic\partials\wpfomo-public-display.php:30
actionadmin_noticeswpfomo.php:77
actionadmin_initwpfomo.php:91
Maintenance & Trust

WPFomo Maintenance & Trust

Maintenance Signals

WordPress version tested5.1.22
Last updatedAug 28, 2019
PHP min version
Downloads20K

Community Trust

Rating100/100
Number of ratings3
Active installs700
Developer Profile

WPFomo Developer Profile

WPDeveloper

46 plugins · 4.0M total installs

73
trust score
Avg Security Score
91/100
Avg Patch Time
163 days
View full developer profile
Detection Fingerprints

How We Detect WPFomo

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wpfomo/admin/css/wpfomo-admin.css/wp-content/plugins/wpfomo/admin/js/wpfomo-repeater.js/wp-content/plugins/wpfomo/admin/js/wpfomo-admin.js
Script Paths
/wp-content/plugins/wpfomo/admin/js/wpfomo-repeater.js/wp-content/plugins/wpfomo/admin/js/wpfomo-admin.js
Version Parameters
wpfomo-admin.css?ver=wpfomo-repeater.js?ver=wpfomo-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
wpfomo-settings-containerwpfomo-settings-titlewpfomo-template
Data Attributes
id="nx-installer-btn"
JS Globals
repeater
Shortcode Output
[primary_text][link_text][secondary_text]
FAQ

Frequently Asked Questions about WPFomo