This plugin gives you the ability to push notifications through Firebase Cloud Messaging

0 active installs v1.0.0 PHP + WP 4.6+ Updated Jun 3, 2021
apicloud-messaging-notificationsfcmfirebaserest
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is HI FCM Safe to Use in 2026?

Generally Safe

Score 85/100

HI FCM has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The plugin "hi-fcm-firebase-cloud-messaging" v1.0.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for a high percentage of its SQL queries and ensuring most output is properly escaped. The absence of dangerous functions, file operations, and recorded vulnerabilities in its history are also strengths, suggesting a generally secure codebase. However, significant concerns arise from its attack surface. With two REST API routes identified as lacking permission callbacks, these entry points are entirely unprotected, posing a direct risk of unauthorized access or manipulation. While taint analysis shows no critical or high severity flows, the unprotected REST API routes create a potential avenue for attackers to inject malicious data or trigger unintended actions if not properly validated and authorized.

Key Concerns

  • REST API routes without permission callbacks
Vulnerabilities
None known

HI FCM Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

HI FCM Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
6 prepared
Unescaped Output
2
29 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

75% prepared8 total queries

Output Escaping

94% escaped31 total outputs
Attack Surface
2 unprotected

HI FCM Attack Surface

Entry Points2
Unprotected2

REST API Routes 2

GET/wp-json/hifcm/v1/fcm/subscribe/includes\class-rest-endpoints.php:10
GET/wp-json/hifcm/v1/fcm/unsubscribeincludes\class-rest-endpoints.php:35
WordPress Hooks 13
actioninithi-fcm.php:123
actioninithi-fcm.php:124
filtermanage_hi_fcm_tokens_posts_columnshi-fcm.php:127
actionmanage_hi_fcm_tokens_posts_custom_columnhi-fcm.php:129
actionmanage_edit-hi_fcm_tokens_sortable_columnshi-fcm.php:130
actionadmin_inithi-fcm.php:132
actionadmin_inithi-fcm.php:133
actionadd_meta_boxeshi-fcm.php:134
actionsave_posthi-fcm.php:136
actionadmin_menuhi-fcm.php:138
actionrest_api_inithi-fcm.php:141
actiondelete_posthi-fcm.php:150
actionsave_posthi-fcm.php:464
Maintenance & Trust

HI FCM Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedJun 3, 2021
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

HI FCM Developer Profile

abdullahmohammed

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect HI FCM

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/hi-fcm-firebase-cloud-messaging/assets/css/admin.css/wp-content/plugins/hi-fcm-firebase-cloud-messaging/assets/css/frontend.css/wp-content/plugins/hi-fcm-firebase-cloud-messaging/assets/js/frontend.js
Version Parameters
hi-fcm-firebase-cloud-messaging/assets/css/admin.css?ver=hi-fcm-firebase-cloud-messaging/assets/css/frontend.css?ver=hi-fcm-firebase-cloud-messaging/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

JS Globals
window.hiFcmFrontend
REST Endpoints
/wp-json/hi-fcm/v1/send-notification/wp-json/hi-fcm/v1/register-device
FAQ

Frequently Asked Questions about HI FCM