
EP Pushcrew (now VWO Engage) Security & Risk Analysis
wordpress.org/plugins/ep-pushcrew-now-vwo-engageWith EP PushCrew, You can add PushCrew (now VWO Engage) browser push notifications to your website in less than a minute.
Is EP Pushcrew (now VWO Engage) Safe to Use in 2026?
Generally Safe
Score 85/100EP Pushcrew (now VWO Engage) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "ep-pushcrew-now-vwo-engage" v1.0.0 exhibits a strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points, coupled with zero dangerous functions and file operations, indicates a limited attack surface. The code also demonstrates good practices in SQL query handling, with 100% using prepared statements, and a high percentage (90%) of output being properly escaped. The presence of a nonce check further bolsters its security. The lack of any recorded vulnerabilities, including critical or high-severity ones, further reinforces this positive assessment. The taint analysis showing zero flows with unsanitized paths is also a significant strength.
While the plugin appears secure due to these factors, the analysis of "capability checks" at 0 is a point of slight concern. Although no direct vulnerabilities were found in this version, a complete absence of capability checks might be a weakness if new entry points were to be introduced in future versions without proper authorization controls. However, given the current very limited attack surface and strong coding practices, the overall risk is assessed as very low. The plugin's history of zero vulnerabilities and lack of critical findings suggests a mature and well-maintained codebase.
Key Concerns
- Zero capability checks present
EP Pushcrew (now VWO Engage) Security Vulnerabilities
EP Pushcrew (now VWO Engage) Code Analysis
Output Escaping
EP Pushcrew (now VWO Engage) Attack Surface
WordPress Hooks 7
Maintenance & Trust
EP Pushcrew (now VWO Engage) Maintenance & Trust
Maintenance Signals
Community Trust
EP Pushcrew (now VWO Engage) Alternatives
PushCrew
pushcrew
With PushCrew, any website on the web can get up and running with browser push notifications in less than a minute.
informvisitors
informvisitors
With informvisitors, you can start sending browser push notifications to your clients in less than a minute.Just install the plugin and enjoy.
PopNotifi
popnotifi
The Push Notifications Revolution by PopNotifi
Web Push Notifications by Aimtell
aimtell-web-push-notifications
Aimtell enables users to re-engage their website visitors with highly targeted mobile & desktop web push notifications.
PushPanda.io – Free Web Push Notifications
pushpanda-free-web-push-notifications
Free web push notifications for destop and mobile browsers. Simply enable the plugin and start sending push messages to your subscribers.
EP Pushcrew (now VWO Engage) Developer Profile
2 plugins · 10 total installs
How We Detect EP Pushcrew (now VWO Engage)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ep-pushcrew-now-vwo-engage/assets/css/eppc-admin.css/wp-content/plugins/ep-pushcrew-now-vwo-engage/assets/js/eppc-admin.jsHTML / DOM Fingerprints
eppc-posttypesname="eppc_options[eppc_start]"name="eppc_options[eppc_hash]"name="eppc_options[eppc_posttypes][]"