
iZooto – Web Push Notifications Security & Risk Analysis
wordpress.org/plugins/izooto-web-pushEngage your audience and drive repeat traffic by delivering relevant and personalized push notifications - across web browsers, Android, iOS and Messe …
Is iZooto – Web Push Notifications Safe to Use in 2026?
Mostly Safe
Score 78/100iZooto – Web Push Notifications is generally safe to use. 1 past CVE were resolved.
The izooto-web-push plugin v3.7.20 exhibits a mixed security posture. While it demonstrates good practices in areas like SQL query preparation and a high percentage of properly escaped output, there are significant concerns regarding its attack surface and lack of authentication checks.
The static analysis reveals one AJAX handler that lacks any authentication checks, presenting a direct entry point for potential malicious activity. Although taint analysis did not uncover critical or high severity vulnerabilities, the two identified flows with unsanitized paths are concerning and warrant further investigation, especially in conjunction with the unprotected AJAX handler. The absence of capability checks and the presence of external HTTP requests also add to the potential attack vectors.
The plugin's vulnerability history is remarkably clean, with no known CVEs. This lack of past issues is a positive indicator, suggesting either a strong development focus on security or limited exposure to sophisticated attacks. However, the presence of unprotected entry points in the current version means that this clean history could be a temporary state. Overall, the plugin has strengths in its handling of SQL and output, but the unprotected AJAX handler and unsanitized paths represent tangible risks that need to be addressed.
Key Concerns
- Unprotected AJAX handler
- Flows with unsanitized paths detected
- Missing capability checks
iZooto – Web Push Notifications Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
iZooto <= 3.7.20 - Missing Authorization
iZooto – Web Push Notifications Release Timeline
iZooto – Web Push Notifications Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
iZooto – Web Push Notifications Attack Surface
AJAX Handlers 1
WordPress Hooks 16
Maintenance & Trust
iZooto – Web Push Notifications Maintenance & Trust
Maintenance Signals
Community Trust
iZooto – Web Push Notifications Alternatives
RollerAds – Web Push Notifications
rollerads
RollerAds - clear and flexible web-push service for webmasters. Push notifications are successfully used to send promotional content, user information …
Web Push Notifications – Webpushr
webpushr-web-push-notifications
Fastest growing & lightweight plugin for Web Push Notifications. Add browser push notifications to your WordPress & WooCommerce site.
Perfecty Push Notifications
perfecty-push-notifications
Push Notifications that are self-hosted, you don't need API keys to integrate with external Push Notifications providers that will charge you lat …
Gravitec.net – Web Push Notifications
gravitec-net-web-push-notifications
Easy-to-use and smart push notifications for your website. Increase subscriptions and repeat visits with minimal effort.
Pushly
pushly
Take user engagement to a whole new level with an easy-to-use platform to engage audiences with targeted content after they leave your site.
iZooto – Web Push Notifications Developer Profile
1 plugin · 1K total installs
How We Detect iZooto – Web Push Notifications
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/izooto-web-push/assets/css/unminified/admin_style.css/wp-content/plugins/izooto-web-push/assets/css/unminified/iznotify_style.css/wp-content/plugins/izooto-web-push/assets/js/unminified/admin_init.js/wp-content/plugins/izooto-web-push/assets/js/unminified/cookies.js/wp-content/plugins/izooto-web-push/assets/js/unminified/iznotify_editor_script.js/wp-content/plugins/izooto-web-push/assets/js/unminified/iznotify_script.jshttps://fonts.googleapis.com/icon?family=Material+IconsHTML / DOM Fingerprints
izooto-wordpressizooto-logoshadow-cardcard-container-heightsection-twoizooto-footerform-control<!--<div class="plugin-container" style="margin-top: 25px;">--><!-- <div class="plugin-header">--><!--class="izooto-logo"> <span> Web Push for WordPress</span>--><!--</div>-->+4 moreid="token"name="token"id="edit-token"id="tokensubmit"name="tokensubmit"id="freshUser"+1 moreparams