
Notifications For ServerChan Security & Risk Analysis
wordpress.org/plugins/notifications-for-serverchanA ServerChan Notification plugin, can send WordPress Event to your WeChat.
Is Notifications For ServerChan Safe to Use in 2026?
Generally Safe
Score 85/100Notifications For ServerChan has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "notifications-for-serverchan" plugin v0.1 presents a concerning security posture despite having no recorded historical vulnerabilities. The static analysis reveals significant weaknesses that outweigh the absence of past exploits. Notably, 100% of the identified outputs are not properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. While the plugin does not directly perform SQL queries without prepared statements and has no file operations or external HTTP requests listed (besides one potentially benign one), the lack of output escaping is a critical flaw. Furthermore, the complete absence of nonce checks and capability checks on all entry points (though there are currently zero entry points detected) suggests a potential for future vulnerabilities if functionality is added without proper security considerations. The lack of taint analysis flows is also a limitation, potentially masking deeper issues. In conclusion, while the plugin is currently small and has no known CVEs, the identified code signals point to an immature security implementation, particularly concerning output sanitization and authorization, which should be addressed proactively.
Key Concerns
- All identified outputs are unescaped
- No nonce checks on entry points
- No capability checks on entry points
- Limited static analysis coverage (0 taint flows)
Notifications For ServerChan Security Vulnerabilities
Notifications For ServerChan Release Timeline
Notifications For ServerChan Code Analysis
Output Escaping
Notifications For ServerChan Attack Surface
WordPress Hooks 4
Maintenance & Trust
Notifications For ServerChan Maintenance & Trust
Maintenance Signals
Community Trust
Notifications For ServerChan Alternatives
MailPoet – Newsletters, Email Marketing, and Automation
mailpoet
Send beautiful newsletters from WordPress. Collect subscribers with signup forms, automate your emails for WooCommerce, blog post notifications & more
Disable Admin Notices – Hide Dashboard Notifications
disable-admin-notices
Disable admin notices and hide dashboard notifications from plugins, themes and core. Hide all notices, selected ones, or show them in a single line.
Manage Notification E-mails
manage-notification-emails
Enable and disable email notifications that WordPress sends to the admin and user. Works perfectly with many other plugins!
My Sticky Bar – Floating Notification Bar & Sticky Header (formerly myStickymenu)
mystickymenu
Create a welcome notification bar for your website. Also, My Sticky Bar plugin can make your menu or header sticky to the top when scrolled 📌
OneSignal – Web Push Notifications
onesignal-free-web-push-notifications
Increase engagement and drive more repeat traffic to your WordPress site with push notifications. Now a WordPress VIP Gold Partner.
Notifications For ServerChan Developer Profile
12 plugins · 180 total installs
How We Detect Notifications For ServerChan
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/notifications-for-serverchan/admin/css/common.css/wp-content/plugins/notifications-for-serverchan/admin/css/style.css/wp-content/plugins/notifications-for-serverchan/admin/js/common.js/wp-content/plugins/notifications-for-serverchan/admin/js/input-number.js/wp-content/plugins/notifications-for-serverchan/admin/js/script.js/wp-content/plugins/notifications-for-serverchan/admin/js/common.js/wp-content/plugins/notifications-for-serverchan/admin/js/input-number.js/wp-content/plugins/notifications-for-serverchan/admin/js/script.jsnotifications-for-serverchan/admin/css/common.css?ver=notifications-for-serverchan/admin/css/style.css?ver=notifications-for-serverchan/admin/js/common.js?ver=notifications-for-serverchan/admin/js/input-number.js?ver=notifications-for-serverchan/admin/js/script.js?ver=HTML / DOM Fingerprints
notifications-for-serverchan-wrappernotifications-sc-settings-formdata-notifications-sc-tokendata-notifications-sc-sendkeywindow.notifications_sc_params