
EPush Notifications Security & Risk Analysis
wordpress.org/plugins/free-web-push-notificationWeb push notification services are the best way to deliver time boud content to customers about your offerings even they are out of your browser.
Is EPush Notifications Safe to Use in 2026?
Generally Safe
Score 85/100EPush Notifications has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "free-web-push-notification" plugin version 1.2 exhibits significant security concerns. A primary issue is its considerable attack surface, with 3 AJAX handlers, all of which lack proper authentication checks. This directly exposes the plugin to potential unauthorized access and manipulation. The static analysis also reveals critical weaknesses in code hygiene: the use of the `unserialize` function without adequate validation is a high-risk practice that can lead to remote code execution vulnerabilities if attacker-controlled data is passed to it. Furthermore, the complete absence of prepared statements for all SQL queries is a major security flaw, making the plugin highly susceptible to SQL injection attacks. The taint analysis confirms these concerns with 2 high-severity flows and 3 unsanitized path flows, indicating potential vulnerabilities where untrusted input can influence program execution in a dangerous way. The plugin's vulnerability history shows no recorded CVEs, which might suggest it has not been widely targeted or has been fortunate, but this does not negate the severe flaws identified in the code itself. The lack of any nonce or capability checks on the identified entry points further exacerbates the risk, leaving the plugin vulnerable to various forms of attack.
Key Concerns
- AJAX handlers without auth checks
- Unserialized data without validation
- SQL queries without prepared statements
- Taint flow: High severity
- Taint flow: Unsanitized paths
- No nonce checks
- No capability checks
- Low output escaping percentage
EPush Notifications Security Vulnerabilities
EPush Notifications Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
EPush Notifications Attack Surface
AJAX Handlers 3
WordPress Hooks 17
Maintenance & Trust
EPush Notifications Maintenance & Trust
Maintenance Signals
Community Trust
EPush Notifications Alternatives
SendPulse Free Web Push
sendpulse-web-push
Web push notifications for your website. Available in Chrome (Android and desktop), Firefox (Android and desktop) and Safari (desktop).
AlertWise: Mobile & Web Push Notification Service
alertwise
AlertWise is a powerful push notification plugin; that helps you engage users in real time.
OneSignal – Web Push Notifications
onesignal-free-web-push-notifications
Increase engagement and drive more repeat traffic to your WordPress site with push notifications. Now a WordPress VIP Gold Partner.
PushEngage – Web Push notification, WA Automation & Multi-Channel Chat Widget ( WA, Messenger, X, Telegram, TikTok & More)
pushengage
Send order updates, recover abandoned carts, and boost retention with push notifications, WhatsApp automation + multichannel Chat widget.
Web Push Notifications – Webpushr
webpushr-web-push-notifications
Fastest growing & lightweight plugin for Web Push Notifications. Add browser push notifications to your WordPress & WooCommerce site.
EPush Notifications Developer Profile
4 plugins · 60 total installs
How We Detect EPush Notifications
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/free-web-push-notification/css/style.css/wp-content/plugins/free-web-push-notification/js/firebase-messaging-sw.jsHTML / DOM Fingerprints
Notify_logo_uploadNotify_logoNotify_logo_urltabstab-linksdata-targetfwpn_push_config_classfwpn_push_notification_menufwpn_extra_post_info_pagefwpn_load_custom_wp_admin_stylefwpn_deactivate_push_notifyfwpn_push_subscription+1 more