
Gravitec.net – Web Push Notifications Security & Risk Analysis
wordpress.org/plugins/gravitec-net-web-push-notificationsEasy-to-use and smart push notifications for your website. Increase subscriptions and repeat visits with minimal effort.
Is Gravitec.net – Web Push Notifications Safe to Use in 2026?
Generally Safe
Score 99/100Gravitec.net – Web Push Notifications has a strong security track record. Known vulnerabilities have been patched promptly.
The gravitec-net-web-push-notifications plugin v2.9.19 exhibits a generally strong security posture, with excellent adherence to best practices in output escaping and prepared SQL statements. The static analysis reveals a minimal attack surface consisting of a single AJAX handler, which is fortunately protected by authentication checks. Taint analysis also indicates no critical or high-severity vulnerabilities related to unsanitized data flows. However, the plugin does have a history of known vulnerabilities, specifically one medium-severity CVE in its past. While currently unpatched CVEs are zero, this history suggests a need for continued vigilance and timely updates. The plugin's use of external HTTP requests and a cron event, while not inherently insecure, are potential areas to monitor for future issues if not carefully implemented.
Overall, the plugin demonstrates good security hygiene with effective sanitization and authorization checks on its entry points. The lack of critical findings in static and taint analysis is a positive sign. The primary area for concern lies in its historical vulnerability record, which, despite being resolved in the current version, necessitates ongoing monitoring and prompt patching of any future discovered flaws to maintain a robust security profile.
Key Concerns
- Medium severity CVE in vulnerability history
- External HTTP requests present
- Cron event present
Gravitec.net – Web Push Notifications Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Gravitec.net – Web Push Notifications <= 2.9.17 - Missing Authorization
Gravitec.net – Web Push Notifications Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Gravitec.net – Web Push Notifications Attack Surface
AJAX Handlers 1
WordPress Hooks 27
Scheduled Events 1
Maintenance & Trust
Gravitec.net – Web Push Notifications Maintenance & Trust
Maintenance Signals
Community Trust
Gravitec.net – Web Push Notifications Alternatives
Web Push Notifications by Aimtell
aimtell-web-push-notifications
Aimtell enables users to re-engage their website visitors with highly targeted mobile & desktop web push notifications.
Push Notifications For Web
push-notifications-for-web
Free, fastest growing & lightweight plugin for Web Push Notifications. Add Free browser push notifications to your WordPress.
PushEngage – Web Push notification, WA Automation & Multi-Channel Chat Widget ( WA, Messenger, X, Telegram, TikTok & More)
pushengage
Send order updates, recover abandoned carts, and boost retention with push notifications, WhatsApp automation + multichannel Chat widget.
Web Push Notifications – Webpushr
webpushr-web-push-notifications
Fastest growing & lightweight plugin for Web Push Notifications. Add browser push notifications to your WordPress & WooCommerce site.
Perfecty Push Notifications
perfecty-push-notifications
Push Notifications that are self-hosted, you don't need API keys to integrate with external Push Notifications providers that will charge you lat …
Gravitec.net – Web Push Notifications Developer Profile
1 plugin · 1K total installs
How We Detect Gravitec.net – Web Push Notifications
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gravitec-net-web-push-notifications/notice.js/wp-content/plugins/gravitec-net-web-push-notifications/build/index.js/wp-content/plugins/gravitec-net-web-push-notifications/build/index.asset.php/wp-content/plugins/gravitec-net-web-push-notifications/assets/css/gravitec-admin.css/wp-content/plugins/gravitec-net-web-push-notifications/assets/js/gravitec-admin.js/wp-content/plugins/gravitec-net-web-push-notifications/notice.js/wp-content/plugins/gravitec-net-web-push-notifications/build/index.js/wp-content/plugins/gravitec-net-web-push-notifications/assets/js/gravitec-admin.jsgravitec-net-web-push-notifications/notice.js?ver=gravitec-net-web-push-notifications/build/index.js?ver=gravitec-net-web-push-notifications/build/index.asset.php?ver=gravitec-net-web-push-notifications/assets/css/gravitec-admin.css?ver=gravitec-net-web-push-notifications/assets/js/gravitec-admin.js?ver=HTML / DOM Fingerprints
gravitec-contentgravitec-admin-wrapgravitec-button-activegravitec-button-inactivegravitec-spinnergravitec-tooltipGravitec.netGravitecnetFor Gravitec developers: replace cdn domain to test domain.Check if current user can edit this post+3 moredata-gravitecdata-gravitec-iddata-gravitec-buttondata-gravitec-subscribegravitecnet_paramsajax_objectgravitec_paramsgravitec/wp-json/gravitecnet/v1/settings/wp-json/gravitecnet/v1/subscribe[gravitec_subscribe_button][gravitec_notification][gravitec_unsubscribe]