WPNotify – Notifications for WooCommerce Security & Risk Analysis

wordpress.org/plugins/wpnotify-notifications-for-woocommerce

Ready to use WhatsApp notifications service plugin for WooCommerce. Install and start sending.

10 active installs v1.0.0 PHP + WP 3.0.1+ Updated Dec 6, 2020
alertsmailnotificationswhatsappwoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WPNotify – Notifications for WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

WPNotify – Notifications for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "wpnotify-notifications-for-woocommerce" plugin v1.0.0 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices regarding SQL queries by exclusively using prepared statements and includes a reasonable number of nonce and capability checks. There is also a lack of known historical vulnerabilities, suggesting a generally stable codebase. However, significant concerns arise from the static analysis. The presence of an unprotected AJAX handler represents a critical attack vector, as it lacks authentication and permission checks, potentially allowing unauthorized actions. Furthermore, the taint analysis reveals that all analyzed flows involve unsanitized paths, though they are not currently classified as critical or high severity. This indicates a potential for vulnerabilities if user input is not properly handled and sanitized in the future. The low percentage of properly escaped output is another concern, increasing the risk of cross-site scripting (XSS) vulnerabilities.

Key Concerns

  • Unprotected AJAX handler
  • Flows with unsanitized paths
  • Low percentage of properly escaped output
Vulnerabilities
None known

WPNotify – Notifications for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

WPNotify – Notifications for WooCommerce Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

WPNotify – Notifications for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
25
15 escaped
Nonce Checks
2
Capability Checks
3
File Operations
1
External Requests
2
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

38% escaped40 total outputs
Data Flows · Security
3 unsanitized

Data Flow Analysis

3 flows3 with unsanitized paths
woonotify_home_page (woonotify.php:79)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

WPNotify – Notifications for WooCommerce Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_wpnotify_activateinclude/classes/woonotify_license.php:8
WordPress Hooks 8
actionwoocommerce_thankyouinclude/classes/woonotify_notify.php:16
actionwoocommerce_order_status_changedinclude/classes/woonotify_notify.php:19
actionwp_enqueue_scriptswoonotify.php:45
actionwp_enqueue_scriptswoonotify.php:46
actionwoocommerce_after_checkout_formwoonotify.php:48
actionwoocommerce_after_checkout_validationwoonotify.php:49
actionadmin_menuwoonotify.php:158
actionadmin_bar_menuwoonotify.php:191
Maintenance & Trust

WPNotify – Notifications for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedDec 6, 2020
PHP min version
Downloads1K

Community Trust

Rating20/100
Number of ratings2
Active installs10
Developer Profile

WPNotify – Notifications for WooCommerce Developer Profile

woonotify

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WPNotify – Notifications for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wpnotify-notifications-for-woocommerce/admin/assets/css/tailwind.min.css/wp-content/plugins/wpnotify-notifications-for-woocommerce/admin/assets/css/app.css/wp-content/plugins/wpnotify-notifications-for-woocommerce/admin/assets/js/app.js
Script Paths
/wp-content/plugins/wpnotify-notifications-for-woocommerce/admin/assets/js/app.js

HTML / DOM Fingerprints

Data Attributes
dashicons dashicons-whatsapp
JS Globals
ajax_url
FAQ

Frequently Asked Questions about WPNotify – Notifications for WooCommerce