Zibad Smart Notifier Security & Risk Analysis

wordpress.org/plugins/zibad-smart-notifier

Smart Notifier helps WooCommerce stores send automated SMS notifications for order events.

0 active installs v1.1.0 PHP 7.4+ WP 5.8+ Updated Feb 28, 2026
abandoned-cartnotificationsorder-statussmswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Zibad Smart Notifier Safe to Use in 2026?

Generally Safe

Score 100/100

Zibad Smart Notifier has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The zibad-smart-notifier plugin v1.1.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by having no known CVEs, no critical or high severity taint flows in the analyzed code, and a strong reliance on prepared statements for its SQL queries. The absence of direct entry points like AJAX handlers, REST API routes, and shortcodes further reduces the immediate attack surface. However, there are areas of concern that temper the overall assessment. The taint analysis revealed flows with unsanitized paths, indicating a potential risk, even if no critical or high severity issues were directly identified from these. Additionally, the plugin relies on the Freemius v1.0 bundled library, which could be outdated and a potential vector for vulnerabilities if not kept current. The significant percentage of improperly escaped output is a notable weakness, increasing the risk of Cross-Site Scripting (XSS) vulnerabilities, especially if the unsanitized paths can lead to user-controlled data being outputted without proper sanitization. While the plugin's vulnerability history is clean, this, combined with the static analysis findings, suggests a need for diligent code review and proactive security measures to address the identified weaknesses, particularly around output escaping and unsanitized paths.

Key Concerns

  • Flows with unsanitized paths found
  • 149 total outputs, 73% properly escaped
  • Bundled Freemius v1.0 library
Vulnerabilities
None known

Zibad Smart Notifier Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Zibad Smart Notifier Release Timeline

v1.1.0Current
Code Analysis
Analyzed Mar 17, 2026

Zibad Smart Notifier Code Analysis

Dangerous Functions
0
Raw SQL Queries
4
14 prepared
Unescaped Output
40
109 escaped
Nonce Checks
4
Capability Checks
1
File Operations
1
External Requests
1
Bundled Libraries
1

Bundled Libraries

Freemius1.0

SQL Query Safety

78% prepared18 total queries

Output Escaping

73% escaped149 total outputs
Data Flows · Security
3 unsanitized

Data Flow Analysis

5 flows3 with unsanitized paths
page_templates (admin\class-zimsn-admin.php:223)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Zibad Smart Notifier Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 26
actionadmin_menuadmin\class-zimsn-admin.php:6
actionadmin_enqueue_scriptsadmin\class-zimsn-admin.php:7
actionadmin_post_zimsn_save_templateadmin\class-zimsn-admin.php:8
actionadmin_post_zimsn_delete_templateadmin\class-zimsn-admin.php:9
actionadmin_post_zimsn_save_workflowsadmin\class-zimsn-admin.php:10
actionadmin_post_zimsn_delete_workflowadmin\class-zimsn-admin.php:11
actionadmin_initadmin\class-zimsn-admin.php:12
actionwoocommerce_cart_loaded_from_sessionincludes\class-zimsn-business-logic-handler.php:9
actionwoocommerce_order_status_completedincludes\class-zimsn-business-logic-handler.php:12
actionwoocommerce_order_status_changedincludes\class-zimsn-business-logic-handler.php:15
actionuser_registerincludes\class-zimsn-business-logic-handler.php:19
filtercron_schedulesincludes\class-zimsn-scheduler.php:7
actionzimsn_process_queueincludes\class-zimsn-scheduler.php:8
actionzimsn_check_abandoned_cartsincludes\class-zimsn-scheduler.php:9
actionwoocommerce_checkout_order_processedintegrations\class-zimsn-woocommerce.php:24
actionwoocommerce_order_status_changedintegrations\class-zimsn-woocommerce.php:27
actionzimsn_check_abandoned_cartsintegrations\class-zimsn-woocommerce.php:30
actionwoocommerce_initintegrations\class-zimsn-woocommerce.php:35
filterwoocommerce_sanitize_additional_fieldintegrations\class-zimsn-woocommerce.php:36
actionwoocommerce_validate_additional_fieldintegrations\class-zimsn-woocommerce.php:37
actionwoocommerce_checkout_update_order_metaintegrations\class-zimsn-woocommerce.php:38
actionwoocommerce_add_to_cartintegrations\class-zimsn-woocommerce.php:40
actionwoocommerce_cart_item_removedintegrations\class-zimsn-woocommerce.php:41
actionwoocommerce_after_cart_item_quantity_updateintegrations\class-zimsn-woocommerce.php:42
actionadmin_noticeszibad-smart-notifier.php:60
actionplugins_loadedzibad-smart-notifier.php:143

Scheduled Events 3

zimsn_process_queue
zimsn_process_queue
zimsn_check_abandoned_carts
Maintenance & Trust

Zibad Smart Notifier Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 28, 2026
PHP min version7.4
Downloads185

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Zibad Smart Notifier Developer Profile

zibadmend

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Zibad Smart Notifier

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/zibad-smart-notifier/admin/css/style.css/wp-content/plugins/zibad-smart-notifier/admin/js/admin.js/wp-content/plugins/zibad-smart-notifier/assets/css/zibad-smart-notifier.css
Version Parameters
zibad-smart-notifier/admin/css/style.css?ver=zibad-smart-notifier/admin/js/admin.js?ver=zibad-smart-notifier/assets/css/zibad-smart-notifier.css?ver=

HTML / DOM Fingerprints

CSS Classes
zibad-smart-notifierzimsn-admin
HTML Comments
<!-- Zibad Smart Notifier Pro Add-on Notice -->
JS Globals
zimsn_admin_ajax_object
FAQ

Frequently Asked Questions about Zibad Smart Notifier