
CleverPush Security & Risk Analysis
wordpress.org/plugins/cleverpushCleverPush lets you send browser push notifications to your users in the simplest way possible.
Is CleverPush Safe to Use in 2026?
Generally Safe
Score 92/100CleverPush has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The CleverPush plugin v1.9.8 exhibits a concerning security posture due to a significant number of unprotected AJAX handlers. All five identified AJAX endpoints lack authentication checks, creating a broad attack surface that could be exploited by unauthenticated users. While the plugin demonstrates good practices in other areas like SQL query preparation and largely proper output escaping, the unprotected AJAX endpoints are a critical weakness. The presence of the `unserialize` function, a known risk for deserialization vulnerabilities if used with untrusted data, further compounds these concerns. The absence of any recorded vulnerability history (CVEs) is a positive sign, suggesting a lack of past exploitable flaws. However, this should not lead to complacency, especially given the current vulnerabilities identified in the static analysis. The plugin's strengths lie in its SQL handling and output escaping, but these are overshadowed by the critical security gaps in its AJAX implementation. Mitigation efforts should prioritize securing these entry points.
Key Concerns
- Unprotected AJAX handlers
- Dangerous function: unserialize
- No nonce checks on AJAX handlers
- Flows with unsanitized paths
CleverPush Security Vulnerabilities
CleverPush Release Timeline
CleverPush Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
CleverPush Attack Surface
AJAX Handlers 5
WordPress Hooks 30
Scheduled Events 1
Maintenance & Trust
CleverPush Maintenance & Trust
Maintenance Signals
Community Trust
CleverPush Alternatives
PushEngage – Web Push Notifications, WooCommerce Automation & Chat Widget
pushengage
The #1 push notification plugin for WordPress & WooCommerce. Recover abandoned carts, automate alerts, and grow subscribers — no code needed.
Digital Conversion – Push Notifications & Marketing Hub
digital-conversion
Smart Web Push with unlimited subscribers, AI insights, A/B testing, automation, WooCommerce integration, and personalization.
NotificationButton – Web Push Notifications for Websites and Online Stores
notification-button
Enable automated Web Push Notifications for your website to engage visitors and provide real-time updates directly to their browsers.
Web Push Notifications – Webpushr
webpushr-web-push-notifications
Fastest growing & lightweight plugin for Web Push Notifications. Add browser push notifications to your WordPress & WooCommerce site.
Perfecty Push Notifications
perfecty-push-notifications
Push Notifications that are self-hosted, you don't need API keys to integrate with external Push Notifications providers that will charge you lat …
CleverPush Developer Profile
1 plugin · 200 total installs
How We Detect CleverPush
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cleverpush/cleverpush-admin.css/wp-content/plugins/cleverpush/cleverpush.js/wp-content/plugins/cleverpush/cleverpush-settings.js/wp-content/plugins/cleverpush/cleverpush-stories.js/wp-content/plugins/cleverpush/cleverpush.js/wp-content/plugins/cleverpush/cleverpush-settings.js/wp-content/plugins/cleverpush/cleverpush-stories.jscleverpush-admin.css?ver=cleverpush.js?ver=cleverpush-settings.js?ver=cleverpush-stories.js?ver=HTML / DOM Fingerprints
cleverpush-subscription-dialogcleverpush-story-headercleverpush-story-contentcleverpush-story-footer<!-- CleverPush subscription dialog --><!-- CleverPush story template -->data-cleverpush-subscription-iddata-cleverpush-post-idwindow.cleverpushvar cleverpush_settings/wp-json/cleverpush/v1/subscribe/wp-json/cleverpush/v1/unsubscribe[cleverpush_subscribe_button][cleverpush_notification]