Notifadz by Adrenalead – Web Push Notifications Security & Risk Analysis

wordpress.org/plugins/notifadz-by-adrenalead-web-push-notifications

With the Notifadz by Adrenalead plugin, start engaging and monetizing your audience via Web Push Notifications in just 10 minutes!

100 active installs v3.0.27 PHP 7.2+ WP 5.2+ Updated Feb 2, 2026
notificationpushpush-messagesweb-pushweb-push-notification
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Notifadz by Adrenalead – Web Push Notifications Safe to Use in 2026?

Generally Safe

Score 100/100

Notifadz by Adrenalead – Web Push Notifications has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "notifadz-by-adrenalead-web-push-notifications" plugin, version 3.0.27, exhibits a concerning security posture primarily due to a significant number of unprotected AJAX endpoints. While the plugin demonstrates good practices in SQL query handling with 100% prepared statements and a high percentage of output escaping, the absence of authorization checks on all 11 identified AJAX handlers presents a substantial attack surface. This means any unauthenticated user could potentially interact with these endpoints, leading to unintended actions or information disclosure if the underlying code is vulnerable. The taint analysis, though limited in scope, did not reveal any critical or high-severity unsanitized flows, and the lack of any recorded past vulnerabilities is a positive indicator. However, the identified weaknesses in authentication for AJAX handlers cannot be overlooked, creating a notable risk.

Key Concerns

  • 11 AJAX handlers without auth checks
  • 8 flows with unsanitized paths
  • 0 capability checks found
  • 89% output properly escaped (11% unescaped)
Vulnerabilities
None known

Notifadz by Adrenalead – Web Push Notifications Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Notifadz by Adrenalead – Web Push Notifications Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
19
155 escaped
Nonce Checks
1
Capability Checks
0
File Operations
4
External Requests
5
Bundled Libraries
0

Output Escaping

89% escaped174 total outputs
Data Flows
8 unsanitized

Data Flow Analysis

8 flows8 with unsanitized paths
notifadz_add_template (includes\ntdz-functions.php:331)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
11 unprotected

Notifadz by Adrenalead – Web Push Notifications Attack Surface

Entry Points11
Unprotected11

AJAX Handlers 11

authwp_ajax_ntdzincludes\ntdz-functions.php:43
authwp_ajax_login_emailincludes\ntdz-functions.php:44
authwp_ajax_get_cgvincludes\ntdz-functions.php:45
authwp_ajax_add_userincludes\ntdz-functions.php:46
authwp_ajax_add_templateincludes\ntdz-functions.php:47
authwp_ajax_update_templateincludes\ntdz-functions.php:48
authwp_ajax_confirm_templateincludes\ntdz-functions.php:49
authwp_ajax_activate_scripts_triggersincludes\ntdz-functions.php:50
authwp_ajax_check_adsincludes\ntdz-functions.php:51
authwp_ajax_get_ads_txtincludes\ntdz-functions.php:52
authwp_ajax_save_default_push_article_preferencesincludes\ntdz-functions.php:53
WordPress Hooks 15
actionadmin_print_scriptsincludes\ntdz-functions.php:39
actionadmin_print_stylesincludes\ntdz-functions.php:40
actionadmin_menuincludes\ntdz-functions.php:41
actionwp_footerincludes\ntdz-functions.php:42
filterquery_varsincludes\ntdz-functions.php:55
actionparse_requestincludes\ntdz-functions.php:56
actionwp_loadedincludes\ntdz-functions.php:58
actionwpincludes\ntdz-functions.php:60
actionnotifadz_adrenalead_hourly_eventincludes\ntdz-functions.php:61
actionwp_insert_postincludes\ntdz-functions.php:63
actionpublish_postincludes\ntdz-functions.php:64
actionpublish_herve_recipeincludes\ntdz-functions.php:65
actionadd_meta_boxesincludes\ntdz-functions.php:66
actionsave_postincludes\ntdz-functions.php:67
actionadmin_enqueue_scriptsincludes\ntdz-functions.php:69

Scheduled Events 1

notifadz_adrenalead_hourly_event
Maintenance & Trust

Notifadz by Adrenalead – Web Push Notifications Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 2, 2026
PHP min version7.2
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

Notifadz by Adrenalead – Web Push Notifications Developer Profile

Adrenalead

1 plugin · 100 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Notifadz by Adrenalead – Web Push Notifications

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Notifadz by Adrenalead – Web Push Notifications