
AdPushup Security & Risk Analysis
wordpress.org/plugins/adpushupMaximize your AdSense Ad Revenue!
Is AdPushup Safe to Use in 2026?
Generally Safe
Score 85/100AdPushup has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the static analysis, the Adpushup plugin v0.9.6 exhibits a generally strong security posture with several positive indicators. The absence of any known CVEs and a clean vulnerability history suggest a good track record. Furthermore, the code demonstrates good practices such as using prepared statements for all SQL queries and a decent percentage of properly escaped output. The presence of a nonce check is also a positive sign. However, the analysis does reveal some areas for concern. The taint analysis flagged two flows with unsanitized paths, which, although not classified as critical or high severity in this specific analysis, represent a potential risk of unexpected behavior or indirect manipulation if not properly handled in a larger context.
While the attack surface appears minimal with no exposed AJAX handlers, REST API routes, shortcodes, or cron events, this also limits the plugin's functionality. The lack of capability checks on any potential entry points, though currently none are identified, could become a concern if future updates introduce new functionalities. The fact that 27% of the output is not properly escaped, while not explicitly leading to a vulnerability in this static analysis, does introduce a risk of cross-site scripting (XSS) if the data being output is user-controlled or sourced from an untrusted location. In conclusion, the plugin has strong foundational security but would benefit from further scrutiny of the unsanitized taint paths and ensuring all outputs are properly escaped to mitigate potential XSS risks.
Key Concerns
- Unsanitized paths in taint analysis
- Percentage of unescaped output
AdPushup Security Vulnerabilities
AdPushup Code Analysis
Output Escaping
Data Flow Analysis
AdPushup Attack Surface
WordPress Hooks 5
Maintenance & Trust
AdPushup Maintenance & Trust
Maintenance Signals
Community Trust
AdPushup Alternatives
Better AdSense Targeting
better-adsense-targeting
Get better targeted ads from Google's AdSense with this plugin. You can also have Google's AdSense Ignore specific sections of your post by …
CODEC Sponsored Content
codec-sponsored-content
Premium monetizing system for quality blogs & publications (English-language websites only.) Generate revenue by displaying a widget with manually …
Increase Rev Optimizer
increase-rev-optimizer
Increase Rev Optimizer helps publisher partners boost their ad revenue through AI-driven optimization. The plugin fetches a remote JSON file containin …
ADS Revenue Sharing
ads-revenue-sharing
A AdSense revenue-sharing plugin, allowing site owners and users to customize ad settings, manage ad positions, and control ad shares seamlessly.
Site Kit by Google – Analytics, Search Console, AdSense, Speed
google-site-kit
Site Kit is a one-stop solution for WordPress users to use everything Google has to offer to make them successful on the web.
AdPushup Developer Profile
2 plugins · 30 total installs
How We Detect AdPushup
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/adpushup/injector.js/wp-content/plugins/adpushup/script.js/wp-content/plugins/adpushup/style.css//ajax.googleapis.com/ajax/libs/jquery/1.11.2/jquery.min.js//e3.adpushup.com/E3WebService/e3//optimize.adpushup.com/adpushup/style.css?ver=adpushup/script.js?ver=HTML / DOM Fingerprints
<!-- AdPushup Begins --><!-- AdPushup Ends -->data-cfasync="false"window.adpushupvar adpvar jsonvar configvar tLvar apjQuery<div id="_ap_wp_content_start" style="display:none"></div><div id="_ap_wp_content_end" style="display:none"></div>