
Kento Notify Security & Risk Analysis
wordpress.org/plugins/kento-notifyNotification bubble for wordpress comments on post
Is Kento Notify Safe to Use in 2026?
Generally Safe
Score 85/100Kento Notify has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "kento-notify" v1.0 plugin exhibits a concerning security posture, primarily due to its unprotected entry points. The static analysis reveals two AJAX handlers, both of which lack authentication checks. This represents a significant attack surface where unauthenticated users could potentially interact with plugin functionalities, leading to unintended consequences or the exploitation of other weaknesses.
While the plugin has no recorded vulnerability history or critical taint flows, the lack of proper output escaping is a notable weakness. This means that data processed by the plugin and displayed to users might not be sanitized, creating a risk of Cross-Site Scripting (XSS) vulnerabilities. The significant portion of SQL queries not using prepared statements (83%) also raises concerns about potential SQL injection vulnerabilities, although no specific flows were identified in the taint analysis.
The absence of known CVEs and a clean vulnerability history is a positive sign, suggesting that the plugin may not have been a target for widespread exploitation or that past issues have been addressed. However, this should not be seen as a guarantee of current security, especially given the identified weaknesses in its attack surface and data handling. The plugin would benefit greatly from implementing proper nonce and capability checks for its AJAX handlers and ensuring all output is properly escaped to mitigate potential XSS risks.
Key Concerns
- AJAX handlers without auth checks
- Output escaping not used
- SQL queries using prepared statements
Kento Notify Security Vulnerabilities
Kento Notify Code Analysis
SQL Query Safety
Output Escaping
Kento Notify Attack Surface
AJAX Handlers 2
WordPress Hooks 1
Maintenance & Trust
Kento Notify Maintenance & Trust
Maintenance Signals
Community Trust
Kento Notify Alternatives
WPFront Notification Bar
wpfront-notification-bar
Easily lets you create a bar on top or bottom to display a notification.
Notifima – WooCommerce Stock Manager, Inventory Management, Waitlist
woocommerce-product-stock-alert
WooCommerce back in stock notifier and stock manager plugin. Manage inventory, enable waitlists, and send stock notifications automatically.
WPFomo
wpfomo
Fomo notification for WordPress.
Dima Take Action
dima-take-action
Easily lets you add a Top/Buttom Banner to display a notification and promotion.
Discourage Search Engines Notifier
discourage-search-engines-notifier
Shows an admin bar icon indicating your site's search engine visibility status.
Kento Notify Developer Profile
20 plugins · 600 total installs
How We Detect Kento Notify
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/kento-notify/js/demo.js/wp-content/plugins/kento-notify/js/jquery.mousewheel.js/wp-content/plugins/kento-notify/js/perfect-scrollbar.js/wp-content/plugins/kento-notify/css/style.css/wp-content/plugins/kento-notify/css/perfect-scrollbar.css/wp-content/plugins/kento-notify/js/demo.js/wp-content/plugins/kento-notify/js/jquery.mousewheel.js/wp-content/plugins/kento-notify/js/perfect-scrollbar.jsHTML / DOM Fingerprints
wp-notify-boxwp-notify-single-boxwp-notify-whowp-notify-comment-singlewp-notify-datewp-notify-bubblewp-notifywp-notify-comments+2 moreoriginal-titlecommentidviewedMyAjax/wp-json/kento-notify<div id='wp-notify' class='wp-notify' ><div class='wp-notify-bubble'></div><div id='wp-notify-comments'></div><div id='wp-notify-comments-box'></div></div><div id='wp-notify-black'></div>