Notifications For ServerChan Security & Risk Analysis

wordpress.org/plugins/notifications-for-serverchan

A ServerChan Notification plugin, can send WordPress Event to your WeChat.

0 active installs v0.1 PHP 7.1+ WP 4.9.8+ Updated Nov 7, 2018
notification
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Notifications For ServerChan Safe to Use in 2026?

Generally Safe

Score 85/100

Notifications For ServerChan has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "notifications-for-serverchan" plugin v0.1 presents a concerning security posture despite having no recorded historical vulnerabilities. The static analysis reveals significant weaknesses that outweigh the absence of past exploits. Notably, 100% of the identified outputs are not properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. While the plugin does not directly perform SQL queries without prepared statements and has no file operations or external HTTP requests listed (besides one potentially benign one), the lack of output escaping is a critical flaw. Furthermore, the complete absence of nonce checks and capability checks on all entry points (though there are currently zero entry points detected) suggests a potential for future vulnerabilities if functionality is added without proper security considerations. The lack of taint analysis flows is also a limitation, potentially masking deeper issues. In conclusion, while the plugin is currently small and has no known CVEs, the identified code signals point to an immature security implementation, particularly concerning output sanitization and authorization, which should be addressed proactively.

Key Concerns

  • All identified outputs are unescaped
  • No nonce checks on entry points
  • No capability checks on entry points
  • Limited static analysis coverage (0 taint flows)
Vulnerabilities
None known

Notifications For ServerChan Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Notifications For ServerChan Release Timeline

v0.1Current
Code Analysis
Analyzed Apr 16, 2026

Notifications For ServerChan Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

0% escaped4 total outputs
Attack Surface

Notifications For ServerChan Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_menuadmin/init.php:3
actionadmin_initadmin/init.php:4
actionuser_registerevents/user.php:2
actioninitnotifications-for-serverchan.php:21
Maintenance & Trust

Notifications For ServerChan Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedNov 7, 2018
PHP min version7.1
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Notifications For ServerChan Developer Profile

Bestony

12 plugins · 180 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Notifications For ServerChan

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/notifications-for-serverchan/admin/css/common.css/wp-content/plugins/notifications-for-serverchan/admin/css/style.css/wp-content/plugins/notifications-for-serverchan/admin/js/common.js/wp-content/plugins/notifications-for-serverchan/admin/js/input-number.js/wp-content/plugins/notifications-for-serverchan/admin/js/script.js
Script Paths
/wp-content/plugins/notifications-for-serverchan/admin/js/common.js/wp-content/plugins/notifications-for-serverchan/admin/js/input-number.js/wp-content/plugins/notifications-for-serverchan/admin/js/script.js
Version Parameters
notifications-for-serverchan/admin/css/common.css?ver=notifications-for-serverchan/admin/css/style.css?ver=notifications-for-serverchan/admin/js/common.js?ver=notifications-for-serverchan/admin/js/input-number.js?ver=notifications-for-serverchan/admin/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
notifications-for-serverchan-wrappernotifications-sc-settings-form
Data Attributes
data-notifications-sc-tokendata-notifications-sc-sendkey
JS Globals
window.notifications_sc_params
FAQ

Frequently Asked Questions about Notifications For ServerChan