
Advanced Notifications Security & Risk Analysis
wordpress.org/plugins/advanced-notificationsAdvanced Notifications allows you to create beautiful custom notifications that appear on pages or posts of your choice.
Is Advanced Notifications Safe to Use in 2026?
Generally Safe
Score 91/100Advanced Notifications has a strong security track record. Known vulnerabilities have been patched promptly.
The "advanced-notifications" plugin version 1.2.9 exhibits a mixed security posture. While it demonstrates good practices such as using prepared statements for all SQL queries and a relatively high percentage of properly escaped output, several areas raise concern. The presence of one unprotected AJAX handler significantly widens the attack surface and represents a direct pathway for potential exploitation. Additionally, the use of the `unserialize` function, a known dangerous function, without apparent sanitization in the analyzed flows is a critical risk. While the vulnerability history shows no currently unpatched CVEs and a single medium-severity vulnerability in the past, this does not negate the immediate risks identified in the static analysis, particularly the unprotected entry point and the dangerous function usage. The plugin's strengths lie in its SQL practices and output escaping, but these are overshadowed by the identified vulnerabilities in its entry points and code execution.
Key Concerns
- Unprotected AJAX handler found
- Dangerous function `unserialize` used
- Flow with unsanitized path found
- Output escaping not fully implemented
- Medium severity vulnerability history
Advanced Notifications Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Advanced Notifications <= 1.2.7 - Missing Authorization
Advanced Notifications Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Advanced Notifications Attack Surface
AJAX Handlers 3
WordPress Hooks 66
Maintenance & Trust
Advanced Notifications Maintenance & Trust
Maintenance Signals
Community Trust
Advanced Notifications Alternatives
MaxBoxy: Make WordPress Floating Content, Popup, Alert Bar
maxboxy
Make Conversion Boxes, Popups, Floats and Inject Any Content in a WorsPress way!
Sales Notifications for WooCommerce – Recent Sales Popup
wc-live-sale-notifications
Sales Notifications for WooCommerce - Recent Sales Popup boosts sales by showing recent orders in a popup with customer and product details.
Courier Notices
courier-notices
Add dismissible and non-dismissible notices throughout your WordPress website with customizable colors, icons, and placement options.
Disable Admin Notices – Hide Dashboard Notifications
disable-admin-notices
Disable admin notices and hide dashboard notifications from plugins, themes and core. Hide all notices, selected ones, or show them in a single line.
Hide Admin Notices
hide-admin-notices
Hide – or show – WordPress Dashboard Notices, Messages, Update Nags etc. ... for everything!
Advanced Notifications Developer Profile
2 plugins · 4K total installs
How We Detect Advanced Notifications
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/advanced-notifications/assets/css/admin-an.css/wp-content/plugins/advanced-notifications/assets/js/admin-an.js/wp-content/plugins/advanced-notifications/assets/css/an.css/wp-content/plugins/advanced-notifications/assets/js/an.js/wp-content/plugins/advanced-notifications/assets/js/admin-an.js/wp-content/plugins/advanced-notifications/assets/js/an.jsadvanced-notifications/assets/css/admin-an.css?ver=advanced-notifications/assets/js/admin-an.js?ver=advanced-notifications/assets/css/an.css?ver=advanced-notifications/assets/js/an.js?ver=HTML / DOM Fingerprints
<!--
*
* Advanced Notifications V 1
* ------------------------------------------------
* Powered by - https://wiliba.com
*
-->admin_an_settingsan_settings