
Notification – Custom Notifications and Alerts for WordPress Security & Risk Analysis
wordpress.org/plugins/notificationTake full control of WordPress emails and notifications. Replace default messages, add custom triggers, and send alerts via email, webhook, Slack, and …
Is Notification – Custom Notifications and Alerts for WordPress Safe to Use in 2026?
Generally Safe
Score 100/100Notification – Custom Notifications and Alerts for WordPress has a strong security track record. Known vulnerabilities have been patched promptly.
The "notification" plugin v9.0.10 exhibits a mixed security posture. While it demonstrates good practices like a high percentage of prepared SQL statements and properly escaped output, a significant concern arises from its attack surface. All four identified AJAX handlers lack authentication checks, presenting a direct pathway for unauthenticated users to interact with potentially sensitive functionality. The absence of any critical or high-severity taint flows is a positive indicator, suggesting that sensitive data is generally handled with care within the codebase. However, the single known medium-severity vulnerability related to Cross-Site Scripting, though patched, indicates a historical tendency for input sanitization issues.
Despite the lack of unpatched CVEs and the generally good code hygiene in areas like SQL and output handling, the presence of unprotected AJAX endpoints is a critical weakness. This could allow for denial-of-service attacks or unauthorized actions if the AJAX handlers perform any operations that should be restricted. The plugin's strengths lie in its adherence to secure coding practices for database queries and output rendering. However, the significant number of unprotected entry points overshadows these strengths, making it a moderate risk due to potential abuse of the exposed AJAX functionality.
Key Concerns
- 4 AJAX handlers without auth checks
- 1 known medium severity CVE
Notification – Custom Notifications and Alerts for WordPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Notification – Custom Notifications and Alerts for WordPress <= 7.2.4 - Authenticated Stored Cross-Site Scripting
Notification – Custom Notifications and Alerts for WordPress Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Notification – Custom Notifications and Alerts for WordPress Attack Surface
AJAX Handlers 4
WordPress Hooks 135
Scheduled Events 2
Maintenance & Trust
Notification – Custom Notifications and Alerts for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Notification – Custom Notifications and Alerts for WordPress Alternatives
Customize WordPress Emails and Alerts – Better Notifications for WP
bnfw
Supercharge your WordPress email notifications using a WYSIWYG editor and shortcodes. Default and new notifications available. Add-ons available.
Email Notification on Login
email-notification-on-login
Receive an email after each successful login with the user information
Simple Login Notification
simple-login-notification
Sends a notification email when admins and other users log in to your site.
Post Status Notifier Lite
post-status-notifier-lite
Notify on every post change: Flexible rules, custom placeholders and support for all post types and taxonomies.
Email notification on admin login
email-notification-on-admin-login
Sends an email to a pointed email address when an admin user logs in
Notification – Custom Notifications and Alerts for WordPress Developer Profile
9 plugins · 51K total installs
How We Detect Notification – Custom Notifications and Alerts for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/notification/resources/js/dist/scripts.js/wp-content/plugins/notification/resources/css/dist/style.css/wp-content/plugins/notification/resources/js/dist/scripts.jsHTML / DOM Fingerprints
notification-fieldnotification-code-editor-fielddata-settingsnotification/notification/v1/repeater-field/select//notification/v1/repeater-field//notification/v1/section-repeater-field/