
Eonet Live Notifications Security & Risk Analysis
wordpress.org/plugins/eonet-live-notificationsEnables live notifications for all your users to get better interactions within your BuddyPress site.
Is Eonet Live Notifications Safe to Use in 2026?
Generally Safe
Score 85/100Eonet Live Notifications has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The eonet-live-notifications plugin, version 1.0.11, exhibits a generally strong security posture based on the provided static analysis. A significant strength is the complete absence of unpatched vulnerabilities in its history and the complete use of prepared statements for SQL queries, indicating good development practices. The plugin also boasts a comprehensive set of nonce checks for its AJAX handlers, which is a critical security measure.
However, there are a few areas of concern. The presence of the `unserialize` function is a potential risk if user-controlled data is passed to it without proper sanitization or validation, as it can lead to remote code execution vulnerabilities. While the static analysis did not identify any specific taint flows related to this, it remains an area to monitor. Additionally, the output escaping is only properly implemented in 71% of cases, suggesting a moderate risk of cross-site scripting (XSS) vulnerabilities if user-supplied data is displayed without adequate sanitization.
Overall, the plugin has a solid foundation with no known external vulnerabilities and good practices around SQL and nonce checks. The primary risks stem from the `unserialize` function and partially unescaped output. The lack of any recorded vulnerabilities, combined with the current security measures, suggests a conscientious development effort, but these specific code signals warrant attention for future updates.
Key Concerns
- Use of unserialize function
- Output escaping not fully implemented
Eonet Live Notifications Security Vulnerabilities
Eonet Live Notifications Code Analysis
Dangerous Functions Found
Output Escaping
Eonet Live Notifications Attack Surface
AJAX Handlers 8
WordPress Hooks 14
Maintenance & Trust
Eonet Live Notifications Maintenance & Trust
Maintenance Signals
Community Trust
Eonet Live Notifications Alternatives
Eonet Live Search
eonet-live-search
Search dynamically in real time through all your site, including pages, posts, members, products & so on.
BuddyPress Live Notification
bp-live-notification
BuddyPress Live Notification adds a Facebook Like realtime user notifications for BuddyPress sites.
BP Better Directories
bp-better-directories
Fancy schmancy BuddyPress member directories.
BuddyPress Admin Notifications
buddypress-admin-notifications
This plugin adds a checkbox in the post/page admin (for the admins and editors) to tell members (notification & email) that an important post has …
SearchWP Live Ajax Search
searchwp-live-ajax-search
Template powered live search for any WordPress theme. Does not require SearchWP, but will utilize it if available.
Eonet Live Notifications Developer Profile
4 plugins · 510 total installs
How We Detect Eonet Live Notifications
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/eonet-live-notifications/core/assets/wp-content/plugins/eonet-live-notifications/component-live-notifications/assets/sounds/01/wp-content/plugins/eonet-live-notifications/component-live-notifications/assets/js/eonet_live_notifications.jseonet-live-notifications/component-live-notifications/assets/js/eonet_live_notifications.js?ver=1.0HTML / DOM Fingerprints
data-slug="live-notifications"EONET_NOTIFICATIONS