
HI FCM Security & Risk Analysis
wordpress.org/plugins/hi-fcm-firebase-cloud-messagingThis plugin gives you the ability to push notifications through Firebase Cloud Messaging
Is HI FCM Safe to Use in 2026?
Generally Safe
Score 85/100HI FCM has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "hi-fcm-firebase-cloud-messaging" v1.0.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for a high percentage of its SQL queries and ensuring most output is properly escaped. The absence of dangerous functions, file operations, and recorded vulnerabilities in its history are also strengths, suggesting a generally secure codebase. However, significant concerns arise from its attack surface. With two REST API routes identified as lacking permission callbacks, these entry points are entirely unprotected, posing a direct risk of unauthorized access or manipulation. While taint analysis shows no critical or high severity flows, the unprotected REST API routes create a potential avenue for attackers to inject malicious data or trigger unintended actions if not properly validated and authorized.
Key Concerns
- REST API routes without permission callbacks
HI FCM Security Vulnerabilities
HI FCM Code Analysis
SQL Query Safety
Output Escaping
HI FCM Attack Surface
REST API Routes 2
WordPress Hooks 13
Maintenance & Trust
HI FCM Maintenance & Trust
Maintenance Signals
Community Trust
HI FCM Alternatives
WooCommerce Legacy REST API
woocommerce-legacy-rest-api
The WooCommerce Legacy REST API, which is now part of WooCommerce itself but will be removed in WooCommerce 9.0.
Advanced Access Manager – Access Governance for WordPress
advanced-access-manager
Access Governance for WordPress. Control roles, users, content, admin areas, and APIs to prevent broken access controls and excessive privileges.
Disable REST API
disable-json-api
Disable the use of the REST API on your website to site users. Now with User Role support!
Make Connector
integromat-connector
Make Connector. Make lets you design, build, and automate by connecting with WordPress in just a few clicks.
JWT Authentication for WP REST API
jwt-authentication-for-wp-rest-api
Extends the WP REST API using JSON Web Tokens Authentication as an authentication method.
HI FCM Developer Profile
1 plugin · 0 total installs
How We Detect HI FCM
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/hi-fcm-firebase-cloud-messaging/assets/css/admin.css/wp-content/plugins/hi-fcm-firebase-cloud-messaging/assets/css/frontend.css/wp-content/plugins/hi-fcm-firebase-cloud-messaging/assets/js/frontend.jshi-fcm-firebase-cloud-messaging/assets/css/admin.css?ver=hi-fcm-firebase-cloud-messaging/assets/css/frontend.css?ver=hi-fcm-firebase-cloud-messaging/assets/js/frontend.js?ver=HTML / DOM Fingerprints
window.hiFcmFrontend/wp-json/hi-fcm/v1/send-notification/wp-json/hi-fcm/v1/register-device