
Noti – Activity Notification Security & Risk Analysis
wordpress.org/plugins/noti-activity-notificationTotally free, infinitely configurable, and powerful website activity monitoring and alerting plugin for WordPress projects of any scale.
Is Noti – Activity Notification Safe to Use in 2026?
Generally Safe
Score 85/100Noti – Activity Notification has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The noti-activity-notification plugin v0.1.0 demonstrates a generally good security posture based on the provided static analysis. The absence of any known CVEs, critical taint flows, and a low percentage of SQL queries not using prepared statements are positive indicators. Furthermore, the plugin implements nonce and capability checks, along with proper output escaping for a significant portion of its code, suggesting a developer consciousness towards common WordPress security vulnerabilities. The attack surface, while present with REST API routes and cron events, appears to be secured with proper authentication and permission checks.
However, a few areas warrant consideration. While the number of file operations and external HTTP requests are not inherently a risk, their context and implementation would need further review to ensure they do not introduce vulnerabilities. The limited number of total flows analyzed in taint analysis and the relatively low count of nonce checks (5) and capability checks (21) compared to the overall code complexity (implied by 39 SQL queries and 54 output points) could indicate potential gaps if the plugin's functionality is more extensive than these metrics suggest.
In conclusion, the plugin shows a strong foundation with good security practices in place. The lack of historical vulnerabilities is encouraging. The main area for improvement would be a more comprehensive taint analysis and potentially an increase in the rigor of checks if the plugin's feature set is more complex. Overall, the current data suggests a low to moderate risk profile, with the potential for hidden risks if deeper analysis is not performed.
Noti – Activity Notification Security Vulnerabilities
Noti – Activity Notification Release Timeline
Noti – Activity Notification Code Analysis
SQL Query Safety
Output Escaping
Noti – Activity Notification Attack Surface
REST API Routes 5
WordPress Hooks 20
Scheduled Events 2
Maintenance & Trust
Noti – Activity Notification Maintenance & Trust
Maintenance Signals
Community Trust
Noti – Activity Notification Alternatives
Activity Monitor Pro
activity-monitor-pro
Comprehensive activity monitoring, undo system, and AI-powered anomaly detection for WordPress.
Simple History – Track, Log, and Audit WordPress Changes
simple-history
Track changes and user activities on your WordPress site. See who created a page, uploaded an attachment, and more, for a complete audit trail.
Social Proof Popups & Real-Time Notifications – Herd Effects
mwp-herd-effect
Boost conversions with real-time social proof popups and user activity notifications, encouraging visitor actions on your WordPress site.
Logify WP – Activity Log & User Audit Log
logify-wp
Logify WP - Activity Log & User Audit Log tracks critical changes, logins, and updates with searchable logs for site security.
LogDash Activity Log
logdash-activity-log
The ultimate solution for tracking activities and security issues on your WordPress site.
Noti – Activity Notification Developer Profile
5 plugins · 101K total installs
How We Detect Noti – Activity Notification
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/noti-activity-notification/assets/css/backend.css/wp-content/plugins/noti-activity-notification/assets/css/frontend.css/wp-content/plugins/noti-activity-notification/assets/js/backend.js/wp-content/plugins/noti-activity-notification/assets/js/frontend.js/wp-content/plugins/noti-activity-notification/assets/js/backend.js/wp-content/plugins/noti-activity-notification/assets/js/frontend.jsnoti-activity-notification/assets/css/backend.css?ver=noti-activity-notification/assets/css/frontend.css?ver=noti-activity-notification/assets/js/backend.js?ver=noti-activity-notification/assets/js/frontend.js?ver=HTML / DOM Fingerprints
noti-input-fieldnoti-form-groupnoti-btnnoti-notification-itemnoti-empty-list-messageThis file is subject to the terms and conditions defined in
* file 'LICENSE', which is part of this source code package.This file is subject to the terms and conditions defined in
file 'LICENSE', which is part of this source code package.data-noti-iddata-noti-typenoti/wp-json/noti/v1/events/wp-json/noti/v1/event-types/wp-json/noti/v1/bulk/event-type/wp-json/noti/v1/setup