
pd Android FCM Push Notification Security & Risk Analysis
wordpress.org/plugins/pd-android-fcmpd Android FCM Push Notification is a plugin through which you can send push notifications directly from your WordPress site to android devices via Fi …
Is pd Android FCM Push Notification Safe to Use in 2026?
Generally Safe
Score 100/100pd Android FCM Push Notification has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "pd-android-fcm" plugin v1.1.8 exhibits significant security concerns due to a high number of unprotected entry points, presenting a broad attack surface. The static analysis reveals that both of its AJAX handlers and both of its REST API routes lack proper authentication or permission checks. This means any unauthenticated user could potentially interact with these endpoints, leading to unintended actions or information disclosure. While the plugin does not appear to use dangerous functions, has no file operations, and makes only one external HTTP request, the lack of nonces on AJAX handlers is a notable omission, increasing the risk of Cross-Site Request Forgery (CSRF) attacks. The output escaping is also mediocre at 51%, which could lead to Cross-Site Scripting (XSS) vulnerabilities in certain scenarios. The vulnerability history is clean, with no recorded CVEs. This could indicate either diligent security practices or simply a lack of prior comprehensive auditing. However, the current static analysis findings strongly suggest areas that require immediate attention to mitigate potential security risks.
Key Concerns
- Unprotected AJAX handlers
- Unprotected REST API routes
- Missing nonce checks on AJAX
- Low output escaping rate
pd Android FCM Push Notification Security Vulnerabilities
pd Android FCM Push Notification Code Analysis
SQL Query Safety
Output Escaping
pd Android FCM Push Notification Attack Surface
AJAX Handlers 2
REST API Routes 2
WordPress Hooks 28
Maintenance & Trust
pd Android FCM Push Notification Maintenance & Trust
Maintenance Signals
Community Trust
pd Android FCM Push Notification Alternatives
RollerAds – Web Push Notifications
rollerads
RollerAds - clear and flexible web-push service for webmasters. Push notifications are successfully used to send promotional content, user information …
Topic-Based Push Notifications for Firebase
topic-based-push-notifications-for-firebase
Professional WordPress plugin for sending Firebase Cloud Messaging (FCM) push notifications to Android apps with advanced targeting and analytics.
OneSignal – Web Push Notifications
onesignal-free-web-push-notifications
Increase engagement and drive more repeat traffic to your WordPress site with push notifications. Now a WordPress VIP Gold Partner.
PushEngage – Web Push notification, WA Automation & Multi-Channel Chat Widget ( WA, Messenger, X, Telegram, TikTok & More)
pushengage
Send order updates, recover abandoned carts, and boost retention with push notifications, WhatsApp automation + multichannel Chat widget.
Web Push Notifications – Webpushr
webpushr-web-push-notifications
Fastest growing & lightweight plugin for Web Push Notifications. Add browser push notifications to your WordPress & WooCommerce site.
pd Android FCM Push Notification Developer Profile
2 plugins · 90 total installs
How We Detect pd Android FCM Push Notification
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pd-android-fcm/js/pd-fcm-admin-script.js/wp-content/plugins/pd-android-fcm/css/pd-fcm-admin-style.css/wp-content/plugins/pd-android-fcm/js/pd-fcm-admin-script.jspd-android-fcm/js/pd-fcm-admin-script.js?ver=pd-android-fcm/css/pd-fcm-admin-style.css?ver=HTML / DOM Fingerprints
pdandroidfcm_post_titlepdandroidfcm_post_datedata-postiddata-actionpd_fcm_admin_object