
Web Push Notifications by Aimtell Security & Risk Analysis
wordpress.org/plugins/aimtell-web-push-notificationsAimtell enables users to re-engage their website visitors with highly targeted mobile & desktop web push notifications.
Is Web Push Notifications by Aimtell Safe to Use in 2026?
Generally Safe
Score 100/100Web Push Notifications by Aimtell has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The overall security posture of the aimtell-web-push-notifications plugin v2.13 appears to be strong, particularly concerning its limited attack surface and the absence of known vulnerabilities. The static analysis shows no AJAX handlers, REST API routes, shortcodes, or cron events exposed without proper authentication or permission checks. Furthermore, all SQL queries utilize prepared statements, and the taint analysis found no unsanitized flows. This indicates a deliberate effort by the developers to adhere to secure coding practices and minimize potential entry points for attackers. The plugin also demonstrates good security practices with the presence of nonce and capability checks, and external HTTP requests are handled within a single instance.
Despite the generally positive findings, there are minor areas for improvement. A notable concern is the relatively low percentage (43%) of properly escaped output. This could leave the plugin susceptible to cross-site scripting (XSS) vulnerabilities if user-supplied data is not sufficiently sanitized before being displayed to the end-user. The presence of a single file operation and a single external HTTP request, while seemingly controlled, warrants careful review to ensure they are implemented securely and do not introduce unintended risks. The bundled Select2 library, while common, should be kept up-to-date to mitigate any potential vulnerabilities within it.
The vulnerability history is exceptionally clean, with zero recorded CVEs across all severity levels and no recorded common vulnerability types. This pattern suggests a development team that is either highly diligent in their security practices, responsive to security issues, or has not yet encountered significant security challenges. In conclusion, the plugin is commendably secure in its structural design and vulnerability management. The primary area of focus for further hardening should be on ensuring all output is consistently and correctly escaped to prevent potential XSS exploits.
Key Concerns
- Low percentage of properly escaped output
Web Push Notifications by Aimtell Security Vulnerabilities
Web Push Notifications by Aimtell Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Web Push Notifications by Aimtell Attack Surface
WordPress Hooks 9
Maintenance & Trust
Web Push Notifications by Aimtell Maintenance & Trust
Maintenance Signals
Community Trust
Web Push Notifications by Aimtell Alternatives
Featured Images in RSS for Mailchimp & More
featured-images-for-rss-feeds
Send images to RSS instantly for free. Output blog or WooCommerce photos to Mailchimp RSS email campaigns, ActiveCampaign, Hubspot, Feedly and more.
Readers From RSS 2 Blog Lite
readers-from-rss-2-blog
Increase Your SALES And BLOG Audience By Turning Your BLOG RSS FEED Into A Powerful MARKETING Machine
RSS Ground
rss-ground
RSSGround.com is a service that helps you streamline and automate all of your content marketing efforts - generation, curation, publishing & display.
Ebay Affiliate System for WordPress
linekal-ebay-affiliate-system
Ebay affiliate system is a simple and easy to use plugin which allows you to display ebay affiliate products on your wordpress blog or website using e …
AlertWise: Mobile & Web Push Notification Service
alertwise
AlertWise is a powerful push notification plugin; that helps you engage users in real time.
Web Push Notifications by Aimtell Developer Profile
1 plugin · 60 total installs
How We Detect Web Push Notifications by Aimtell
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/aimtell-web-push-notifications/assets/js/aimtell-worker.js.php/wp-content/plugins/aimtell-web-push-notifications/assets/json/aimtell-manifest.json//s3.amazonaws.com/cdn.aimtell.com/trackpush/trackpush.min.jsHTML / DOM Fingerprints
<!-- start aimtell tracking code --><!-- end aimtell tracking code --><!-- start aimtell abandoned browse tracking code --><!-- end aimtell abandoned browse tracking code -->data-cfasync='false'window._atwindow._aimtellAbandonedBrowseDelaywindow._aimtellBrowseAbandonedwindow._aimtellTimeoutwindow._aimtellGetTrackProductwindow._aimtellResetTimer+1 more