
ONC Master (One Signal Notification Controller) Security & Risk Analysis
wordpress.org/plugins/onc-masterThis plugin is an addon to OneSignal, offres segmenting your one signal user's data by Tag for your Pages post and Customs Post.
Is ONC Master (One Signal Notification Controller) Safe to Use in 2026?
Generally Safe
Score 85/100ONC Master (One Signal Notification Controller) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "onc-master" v1.0.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, making no external HTTP requests, and utilizing prepared statements for all SQL queries. The presence of nonce and capability checks, even if only one each, is also a positive indicator. However, a significant concern arises from the attack surface. The plugin exposes one AJAX handler that lacks authentication checks, creating a direct entry point for unauthenticated attackers. Furthermore, the taint analysis reveals two flows with unsanitized paths, which, although not classified as critical or high severity in this analysis, represent potential avenues for injection attacks if user-supplied data is not properly handled within these flows.
The plugin's vulnerability history is currently clean, with no recorded CVEs. This suggests a relatively secure past, but it's crucial to remember that this is a snapshot in time. The lack of historical vulnerabilities doesn't negate the risks identified in the static analysis. The primary weaknesses lie in the unprotected AJAX endpoint and the unsanitized data flows. While the plugin has strengths in SQL handling and avoiding certain risky practices, the identified entry points require immediate attention to mitigate potential security breaches.
Key Concerns
- AJAX handler without authentication check
- Flows with unsanitized paths
- Low percentage of properly escaped output
ONC Master (One Signal Notification Controller) Security Vulnerabilities
ONC Master (One Signal Notification Controller) Code Analysis
Output Escaping
Data Flow Analysis
ONC Master (One Signal Notification Controller) Attack Surface
AJAX Handlers 1
WordPress Hooks 17
Maintenance & Trust
ONC Master (One Signal Notification Controller) Maintenance & Trust
Maintenance Signals
Community Trust
ONC Master (One Signal Notification Controller) Alternatives
No alternatives data available yet.
ONC Master (One Signal Notification Controller) Developer Profile
3 plugins · 30 total installs
How We Detect ONC Master (One Signal Notification Controller)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/onc-master/css/onc_master-admin.css/wp-content/plugins/onc-master/js/onc_master-admin.jsonc_master-admin.css?ver=onc_master-admin.js?ver=HTML / DOM Fingerprints
page=onc_master