
iZooto – Web Push Notifications Security & Risk Analysis
wordpress.org/plugins/izooto-web-pushEngage your audience and drive repeat traffic by delivering relevant and personalized push notifications - across web browsers, Android, iOS and Messe …
Is iZooto – Web Push Notifications Safe to Use in 2026?
Generally Safe
Score 100/100iZooto – Web Push Notifications has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The izooto-web-push plugin v3.7.20 exhibits a mixed security posture. While it demonstrates good practices in areas like SQL query preparation and a high percentage of properly escaped output, there are significant concerns regarding its attack surface and lack of authentication checks.
The static analysis reveals one AJAX handler that lacks any authentication checks, presenting a direct entry point for potential malicious activity. Although taint analysis did not uncover critical or high severity vulnerabilities, the two identified flows with unsanitized paths are concerning and warrant further investigation, especially in conjunction with the unprotected AJAX handler. The absence of capability checks and the presence of external HTTP requests also add to the potential attack vectors.
The plugin's vulnerability history is remarkably clean, with no known CVEs. This lack of past issues is a positive indicator, suggesting either a strong development focus on security or limited exposure to sophisticated attacks. However, the presence of unprotected entry points in the current version means that this clean history could be a temporary state. Overall, the plugin has strengths in its handling of SQL and output, but the unprotected AJAX handler and unsanitized paths represent tangible risks that need to be addressed.
Key Concerns
- Unprotected AJAX handler
- Flows with unsanitized paths detected
- Missing capability checks
iZooto – Web Push Notifications Security Vulnerabilities
iZooto – Web Push Notifications Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
iZooto – Web Push Notifications Attack Surface
AJAX Handlers 1
WordPress Hooks 16
Maintenance & Trust
iZooto – Web Push Notifications Maintenance & Trust
Maintenance Signals
Community Trust
iZooto – Web Push Notifications Alternatives
RollerAds – Web Push Notifications
rollerads
RollerAds - clear and flexible web-push service for webmasters. Push notifications are successfully used to send promotional content, user information …
PushEngage – Web Push notification, WA Automation & Multi-Channel Chat Widget ( WA, Messenger, X, Telegram, TikTok & More)
pushengage
Send order updates, recover abandoned carts, and boost retention with push notifications, WhatsApp automation + multichannel Chat widget.
Web Push Notifications – Webpushr
webpushr-web-push-notifications
Fastest growing & lightweight plugin for Web Push Notifications. Add browser push notifications to your WordPress & WooCommerce site.
Perfecty Push Notifications
perfecty-push-notifications
Push Notifications that are self-hosted, you don't need API keys to integrate with external Push Notifications providers that will charge you lat …
Gravitec.net – Web Push Notifications
gravitec-net-web-push-notifications
Easy-to-use and smart push notifications for your website. Increase subscriptions and repeat visits with minimal effort.
iZooto – Web Push Notifications Developer Profile
1 plugin · 1K total installs
How We Detect iZooto – Web Push Notifications
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/izooto-web-push/assets/css/unminified/admin_style.css/wp-content/plugins/izooto-web-push/assets/css/unminified/iznotify_style.css/wp-content/plugins/izooto-web-push/assets/js/unminified/admin_init.js/wp-content/plugins/izooto-web-push/assets/js/unminified/cookies.js/wp-content/plugins/izooto-web-push/assets/js/unminified/iznotify_editor_script.js/wp-content/plugins/izooto-web-push/assets/js/unminified/iznotify_script.jshttps://fonts.googleapis.com/icon?family=Material+IconsHTML / DOM Fingerprints
izooto-wordpressizooto-logoshadow-cardcard-container-heightsection-twoizooto-footerform-control<!--<div class="plugin-container" style="margin-top: 25px;">--><!-- <div class="plugin-header">--><!--class="izooto-logo"> <span> Web Push for WordPress</span>--><!--</div>-->+4 moreid="token"name="token"id="edit-token"id="tokensubmit"name="tokensubmit"id="freshUser"+1 moreparams