
JavaScript Notifier Security & Risk Analysis
wordpress.org/plugins/javascript-notifierJavaScript Notifier allows you to inform visitors that your website requires JavaScript.
Is JavaScript Notifier Safe to Use in 2026?
Generally Safe
Score 99/100JavaScript Notifier has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The javascript-notifier plugin version 1.2.9 exhibits a generally good security posture in its static analysis, with no identified dangerous functions, all SQL queries using prepared statements, and no file operations or external HTTP requests. The attack surface is minimal, with zero identified entry points that are unprotected. Taint analysis also shows no critical or high severity flows. However, a significant concern arises from the historical vulnerability data, which shows one known CVE with a medium severity, specifically Cross-site Scripting (XSS). While this vulnerability is currently marked as patched, the existence of a past XSS vulnerability, even if resolved, indicates a potential area of weakness for the plugin. The low percentage of properly escaped outputs (89%) is a minor concern, suggesting a small risk of XSS in the remaining 11% of outputs that were not properly escaped.
Despite the clean static analysis and zero current unpatched vulnerabilities, the history of a medium severity XSS flaw warrants attention. While the plugin has demonstrated the ability to fix such issues, it highlights the need for ongoing vigilance. The low rate of unescaped outputs, while not critical, could be improved to further harden the plugin against potential future XSS attempts. Overall, the plugin appears to be well-developed from a static analysis perspective, but the past vulnerability serves as a reminder that continuous security review and best practices are essential for maintaining a secure plugin.
Key Concerns
- Past medium severity XSS vulnerability
- 11% of outputs not properly escaped
JavaScript Notifier Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
JavaScript Notifier <= 1.2.8 - Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Settings
JavaScript Notifier Code Analysis
Output Escaping
JavaScript Notifier Attack Surface
WordPress Hooks 6
Maintenance & Trust
JavaScript Notifier Maintenance & Trust
Maintenance Signals
Community Trust
JavaScript Notifier Alternatives
Wp Js Detect
wp-js-detect
This plugin is used to display a notification message if the browser's Javascript is disabled. Travis CI
ReCaptcha JS Alert
recaptcha-js-alert
ReCaptcha JS Alert provides the [recaptcha-js-alert] shortcode, which (if necessary) informs visitors of your website that a form requires JavaScript …
Disable WordPress Update Notifications and auto-update Email Notifications
disable-update-notifications
Disables WordPress core update notification and plugins update notification update checks and notifications.
Casper’s Leave Notice
caspers-leave-notice
A quick, easy way to notify your users when they are leaving your site. You can edit the content and add domain exclusions.
Easy Admin Notification
easy-admin-notification
Tested up to 3.3.1 Stable Tag: 1.4 Adds the ability to create easily notification in the admin panel
JavaScript Notifier Developer Profile
4 plugins · 10K total installs
How We Detect JavaScript Notifier
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/javascript-notifier/css/javascript-notifier.css/wp-content/plugins/javascript-notifier/js/javascript-notifier-admin.js/wp-content/plugins/javascript-notifier/js/javascript-notifier-admin.jsjavascript-notifier/css/javascript-notifier.css?ver=javascript-notifier/js/javascript-notifier-admin.js?ver=HTML / DOM Fingerprints
javascript_notifier<!-- JavaScript Notifier --><!-- End JavaScript Notifier -->id="javascript_notifier_block"id="javascript_notifier_block_2"id="javascript_notifier_block_3"id="javascript_notifier_bar"data-default-colorclass="wp_color_picker"JAVASCRIPT_NOTIFIER_VERSION