NotificationButton – Web Push Notifications for Websites and Online Stores Security & Risk Analysis

wordpress.org/plugins/notification-button

Enable automated Web Push Notifications for your website to engage visitors and provide real-time updates directly to their browsers.

0 active installs v1.0.1 PHP 7.2+ WP 5.0+ Updated Jan 9, 2026
browser-notificationsmarketingpush-notificationsweb-pushwebsite-notifications
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is NotificationButton – Web Push Notifications for Websites and Online Stores Safe to Use in 2026?

Generally Safe

Score 100/100

NotificationButton – Web Push Notifications for Websites and Online Stores has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The 'notification-button' plugin v1.0.1 exhibits a generally strong security posture based on the provided static analysis. The complete absence of detectable attack surface points like AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's exposure to potential external attacks. Furthermore, the code signals indicate diligent security practices, with no dangerous functions identified, all SQL queries using prepared statements, and all output being properly escaped. The lack of file operations and external HTTP requests also reduces the risk of common plugin vulnerabilities. The vulnerability history is also clean, with no recorded CVEs, which suggests a track record of secure development or a very low profile that hasn't attracted specific security research.

However, the analysis does reveal some areas that, while not currently exploited or evident as vulnerabilities, could be considered potential weaknesses. The complete lack of nonce checks and capability checks across all entry points (even though there are none reported) is a notable omission. If any entry points were to be introduced in future versions, the absence of these fundamental WordPress security measures would create immediate vulnerabilities. The zero taint analysis flows, while positive, could also be attributed to the limited attack surface. A more comprehensive analysis with potential entry points would provide greater assurance.

In conclusion, the current version of 'notification-button' appears to be very secure due to its minimal attack surface and sound coding practices observed in the static analysis. The absence of any historical vulnerabilities is a significant positive. The primary concern lies in the potential for future introduction of vulnerabilities if new features are added without implementing robust authentication and authorization checks, as these foundational security mechanisms are currently absent. Users should be cautious about future updates if they introduce new user-facing features without addressing these potential gaps.

Key Concerns

  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

NotificationButton – Web Push Notifications for Websites and Online Stores Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

NotificationButton – Web Push Notifications for Websites and Online Stores Release Timeline

v1.0.1Current
Code Analysis
Analyzed Mar 17, 2026

NotificationButton – Web Push Notifications for Websites and Online Stores Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

NotificationButton – Web Push Notifications for Websites and Online Stores Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actioninitindex.php:22
filterquery_varsindex.php:29
actiontemplate_redirectindex.php:37
actionwp_enqueue_scriptsindex.php:52
Maintenance & Trust

NotificationButton – Web Push Notifications for Websites and Online Stores Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedJan 9, 2026
PHP min version7.2
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

NotificationButton – Web Push Notifications for Websites and Online Stores Developer Profile

scordeveloper

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect NotificationButton – Web Push Notifications for Websites and Online Stores

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
https://notificationbutton.com/assets/files/ntButton.min.js
Version Parameters
notificationbuttonpush-custom-script

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about NotificationButton – Web Push Notifications for Websites and Online Stores