
NotifyRabbit Push Security & Risk Analysis
wordpress.org/plugins/notifyrabbit-pushA lightweight WordPress plugin to integrate NotifyRabbit web push notifications into your site.
Is NotifyRabbit Push Safe to Use in 2026?
Generally Safe
Score 100/100NotifyRabbit Push has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "notifyrabbit-push" plugin version 1.0.0 demonstrates a generally strong security posture based on the provided static analysis. The complete absence of identified dangerous functions, unsanitized taint flows, raw SQL queries, and a minimal attack surface are positive indicators. The plugin also seems to adhere to good practices regarding output escaping and capability checks, with a very high percentage of outputs being properly escaped and a reasonable number of capability checks present. Furthermore, the plugin's vulnerability history is entirely clean, with no recorded CVEs, which suggests a history of secure development or diligent patching if any issues did arise in the past.
Despite these strengths, a minor area for consideration is the presence of external HTTP requests without further detail on their handling. While not an immediate red flag, if these requests handle user-supplied data or interact with sensitive external services, they could potentially introduce vulnerabilities if not rigorously validated and sanitized server-side. The low number of total entry points and zero unprotected entry points is a significant strength, minimizing the immediate avenues for attack. Overall, the plugin appears to be developed with security in mind, and the current version presents a low risk, with the primary area for vigilance being the secure implementation of its external communications.
Key Concerns
- External HTTP requests present
NotifyRabbit Push Security Vulnerabilities
NotifyRabbit Push Release Timeline
NotifyRabbit Push Code Analysis
Output Escaping
NotifyRabbit Push Attack Surface
WordPress Hooks 8
Maintenance & Trust
NotifyRabbit Push Maintenance & Trust
Maintenance Signals
Community Trust
NotifyRabbit Push Alternatives
Web Push Notifications by Aimtell
aimtell-web-push-notifications
Aimtell enables users to re-engage their website visitors with highly targeted mobile & desktop web push notifications.
AlertWise: Mobile & Web Push Notification Service
alertwise
AlertWise is a powerful push notification plugin; that helps you engage users in real time.
Digital Conversion – Push Notifications & Marketing Hub
digital-conversion
Smart Web Push with unlimited subscribers, AI insights, A/B testing, automation, WooCommerce integration, and personalization.
NotificationButton – Web Push Notifications for Websites and Online Stores
notification-button
Enable automated Web Push Notifications for your website to engage visitors and provide real-time updates directly to their browsers.
PushRelay – Push Notifications
pushrelay
Send web push notifications to bring visitors back to your WordPress site.
NotifyRabbit Push Developer Profile
1 plugin · 0 total installs
How We Detect NotifyRabbit Push
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
https://notifyrabbit.com/plugins/web/v1/notifyrabbit-sdk.min.jsHTML / DOM Fingerprints
notifyrabbit_meta_noncenotifyrabbit_sendnotifyrabbit_titlenotifyrabbit_messagenotifyrabbit_force_notifyrabbit_send+4 morewindow.NotifyRabbitConfigs