
WPFomo Security & Risk Analysis
wordpress.org/plugins/wpfomoFomo notification for WordPress.
Is WPFomo Safe to Use in 2026?
Generally Safe
Score 85/100WPFomo has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "wpfomo" v1.1.0 exhibits a generally strong security posture based on the static analysis. The complete absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is commendable. The presence of nonce and capability checks on all identified entry points is a significant positive, indicating that the developers have implemented fundamental security measures to protect against common attacks like CSRF and unauthorized access. The lack of any recorded vulnerabilities in its history further bolsters this positive impression.
However, a significant concern arises from the output escaping. With 54% of outputs properly escaped, a substantial portion (46%) remains unescaped. This presents a risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected into the plugin's output, impacting users. While taint analysis reported zero flows, this might be due to the limited scope or complexity of the plugin's code, and the unescaped output is a direct indicator of potential XSS vectors. The attack surface, though small, is entirely reliant on the implemented capability checks for its protection, making the unescaped output the primary area of concern.
In conclusion, "wpfomo" v1.1.0 demonstrates good foundational security practices with robust input validation and access control. Its vulnerability-free history is a positive sign. The main weakness lies in the inconsistent output escaping, which requires immediate attention to mitigate potential XSS risks.
Key Concerns
- 46% of outputs are not properly escaped
WPFomo Security Vulnerabilities
WPFomo Code Analysis
Output Escaping
WPFomo Attack Surface
AJAX Handlers 1
Shortcodes 3
WordPress Hooks 12
Maintenance & Trust
WPFomo Maintenance & Trust
Maintenance Signals
Community Trust
WPFomo Alternatives
NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar
notificationx
Want to boost business trust & conversions? 97% of visitors hesitate to buy because of credibility. Instantly succeed with WooCommerce Sales Alert!
FOMO & Social Proof Notifications by TrustPulse – Best WordPress FOMO Plugin
trustpulse-api
TrustPulse is a FOMO social proof plugin that leverages the power of social proof to instantly boost site conversions by up to 15%!
Notifima – WooCommerce Stock Manager, Inventory Management, Waitlist
woocommerce-product-stock-alert
WooCommerce back in stock notifier and stock manager plugin. Manage inventory, enable waitlists, and send stock notifications automatically.
ProveSource Social Proof
provesource
ProveSource Social Proof increases conversions by up to 17%, boost trust with woocommerce sales notifications and reviews, increase your credibility!
WiserNotify – Social Proof & FOMO Notifications, WooCommerce Sales Popups, Reviews & Announcement Bar
wiser-notify
Boost trust & sales with WiserNotify! Show sign-ups, sales popups & reviews. Convert faster with Social proof & FOMO widgets.
WPFomo Developer Profile
46 plugins · 4.0M total installs
How We Detect WPFomo
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpfomo/admin/css/wpfomo-admin.css/wp-content/plugins/wpfomo/admin/js/wpfomo-repeater.js/wp-content/plugins/wpfomo/admin/js/wpfomo-admin.js/wp-content/plugins/wpfomo/admin/js/wpfomo-repeater.js/wp-content/plugins/wpfomo/admin/js/wpfomo-admin.jswpfomo-admin.css?ver=wpfomo-repeater.js?ver=wpfomo-admin.js?ver=HTML / DOM Fingerprints
wpfomo-settings-containerwpfomo-settings-titlewpfomo-templateid="nx-installer-btn"repeater[primary_text][link_text][secondary_text]