Notification Master – Real-Time WordPress Notifications With Email, SMS, Webhooks & More Security & Risk Analysis

wordpress.org/plugins/notification-master

Send push, email, and real-time notifications across 12+ channels like WhatsApp, Slack, and Discord. Boost engagement automatically.

500 active installs v1.6.9 PHP 7.1+ WP 4.9+ Updated Dec 8, 2025
emailnotificationssmsweb-pushwhatsapp
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Notification Master – Real-Time WordPress Notifications With Email, SMS, Webhooks & More Safe to Use in 2026?

Generally Safe

Score 100/100

Notification Master – Real-Time WordPress Notifications With Email, SMS, Webhooks & More has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The notification-master plugin, version 1.6.9, presents a generally strong security posture based on the static analysis. A significant strength is the complete absence of unprotected entry points across AJAX handlers, REST API routes, shortcodes, and cron events. The code demonstrates good practices with a high percentage of SQL queries using prepared statements and output being properly escaped. Furthermore, the plugin has no known vulnerabilities (CVEs) and no history of past security issues, which is a positive indicator of developer diligence and code quality. However, a few areas warrant attention. While no dangerous functions or unsanitized taint flows were identified, the presence of 71 SQL queries means that the 30% not using prepared statements could be a potential attack vector if not handled with extreme care. The plugin also makes 9 external HTTP requests, which, while not inherently a vulnerability, introduces a dependency on external services that could be compromised or become unavailable, indirectly affecting the plugin's security. Finally, the total of 6 entry points, though all protected, still represents a surface that needs ongoing monitoring and maintenance.

Key Concerns

  • SQL queries without prepared statements
  • External HTTP requests
Vulnerabilities
None known

Notification Master – Real-Time WordPress Notifications With Email, SMS, Webhooks & More Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Notification Master – Real-Time WordPress Notifications With Email, SMS, Webhooks & More Code Analysis

Dangerous Functions
0
Raw SQL Queries
21
50 prepared
Unescaped Output
7
82 escaped
Nonce Checks
5
Capability Checks
17
File Operations
0
External Requests
9
Bundled Libraries
0

SQL Query Safety

70% prepared71 total queries

Output Escaping

92% escaped89 total outputs
Data Flows
All sanitized

Data Flow Analysis

3 flows
generate_token (includes\integrations\class-instagram-integration.php:111)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Notification Master – Real-Time WordPress Notifications With Email, SMS, Webhooks & More Attack Surface

Entry Points6
Unprotected0

AJAX Handlers 4

authwp_ajax_ntfm_dismiss_review_noticeincludes\admin\class-review-notice.php:30
authwp_ajax_notification_master_send_test_notificationincludes\integrations\class-email-integration.php:60
authwp_ajax_notification_master_generate_instagram_access_tokenincludes\integrations\class-instagram-integration.php:68
authwp_ajax_ntfm_generate_keysincludes\webpush\class-loader.php:66

Shortcodes 2

[notification-master-subscribe-btn] includes\webpush\class-loader.php:60
[notification-master-floating-button] includes\webpush\class-loader.php:63
WordPress Hooks 38
actionnotification_master_before_process_connectionincludes\abstracts\class-integration.php:90
actionnotification_master_after_process_connectionincludes\abstracts\class-integration.php:91
filternotification_master_integrationsincludes\abstracts\class-integration.php:92
filternotification_master_triggersincludes\abstracts\class-trigger.php:79
actionadmin_enqueue_scriptsincludes\admin\class-admin.php:60
actionadmin_menuincludes\admin\class-admin.php:70
actionadmin_noticesincludes\admin\class-admin.php:73
filterupload_mimesincludes\admin\class-admin.php:79
filterwp_check_filetype_and_extincludes\admin\class-admin.php:80
actionadmin_noticesincludes\admin\class-review-notice.php:27
actionntfm_process_delayed_post_notificationincludes\class-delayed-notifications.php:56
actioninitincludes\class-logger.php:54
actionntfm_delete_logsincludes\class-logger.php:55
actioninitincludes\class-notification-logger.php:53
actionntfm_notifications_delete_logsincludes\class-notification-logger.php:54
actioninitincludes\class-notifications.php:52
actionrest_api_initincludes\class-notifications.php:55
actionplugins_loadedincludes\class-plugin.php:82
actioninitincludes\class-plugin.php:90
actionadmin_initincludes\class-plugin.php:92
actionntfm_cleanup_failed_subscriptionsincludes\class-plugin.php:95
actioninitincludes\class-plugin.php:96
actionadmin_initincludes\integrations\class-instagram-integration.php:66
actionnotification_master_refresh_instagram_tokenincludes\integrations\class-instagram-integration.php:70
filternotification_master_integrationsincludes\integrations\class-loader.php:68
actioninitincludes\merge-tags\class-loader.php:85
actionrest_api_initincludes\rest-api\class-rest-api.php:52
actioninitincludes\triggers\class-loader.php:103
filterntfm_plugin_merge_tagsincludes\triggers\plugin\class-plugin-updated.php:55
filterntfm_user_merge_tagsincludes\triggers\user\class-user-login.php:55
filterntfm_user_merge_tagsincludes\triggers\user\class-user-registration.php:55
filterallow_password_resetincludes\triggers\user\class-user-registration.php:109
actionwp_enqueue_scriptsincludes\webpush\class-loader.php:56
actionwp_headincludes\webpush\class-loader.php:57
filternotification_master_admin_configincludes\webpush\class-loader.php:68
actionwp_footerincludes\webpush\class-loader.php:70
actionnotification_master_send_webpushincludes\webpush\class-loader.php:72
actionplugins_loadednotifications-master.php:45

Scheduled Events 4

ntfm_delete_logs
ntfm_notifications_delete_logs
ntfm_cleanup_failed_subscriptions
notification_master_refresh_instagram_token
Maintenance & Trust

Notification Master – Real-Time WordPress Notifications With Email, SMS, Webhooks & More Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 8, 2025
PHP min version7.1
Downloads8K

Community Trust

Rating100/100
Number of ratings4
Active installs500
Developer Profile

Notification Master – Real-Time WordPress Notifications With Email, SMS, Webhooks & More Developer Profile

Notification Master

1 plugin · 500 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Notification Master – Real-Time WordPress Notifications With Email, SMS, Webhooks & More

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/notification-master/dist/index.js/wp-content/plugins/notification-master/dist/style.css
Script Paths
/wp-content/plugins/notification-master/dist/index.js
Version Parameters
notification-master/dist/index.js?ver=notification-master/dist/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
ntfm-home
Data Attributes
data-name="solid logo"id="solid_logo"
JS Globals
NotificationsMasterConfig
FAQ

Frequently Asked Questions about Notification Master – Real-Time WordPress Notifications With Email, SMS, Webhooks & More