
Push notification for Mobile and Web app Security & Risk Analysis
wordpress.org/plugins/push-notification-mobile-and-web-appPush notification for Android, iOS and the Web
Is Push notification for Mobile and Web app Safe to Use in 2026?
Generally Safe
Score 99/100Push notification for Mobile and Web app has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin "push-notification-mobile-and-web-app" v2.0.4 exhibits a generally positive security posture with good practices in place. The static analysis reveals no critical or high-severity taint flows, and a very high percentage of SQL queries are prepared, which significantly mitigates SQL injection risks. File operations are absent, reducing the attack surface related to arbitrary file writes. However, there are a few areas for concern. The lack of nonce checks across all entry points is a significant weakness, potentially leaving the application vulnerable to Cross-Site Request Forgery (CSRF) attacks if any unprotected AJAX handlers were present. Additionally, the output escaping is only 40% proper, indicating potential for Cross-Site Scripting (XSS) vulnerabilities in rendered content. The vulnerability history shows one past medium-severity vulnerability, which was a "Missing Authorization" issue. While currently unpatched vulnerabilities are zero, the historical pattern of authorization issues, coupled with the absence of robust authorization checks in the static analysis (only one capability check is noted), suggests a recurring risk that requires attention. Overall, while the plugin avoids some common pitfalls like raw SQL and unpatched critical vulnerabilities, the lack of comprehensive authorization and output sanitization, along with the absence of nonces, presents tangible risks that should be addressed.
Key Concerns
- No nonce checks on entry points
- Low percentage of properly escaped output
- Only 1 capability check found
- 1 past medium severity CVE (Missing Authorization)
Push notification for Mobile and Web app Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Push notification for Mobile and Web app <= 2.0.3 - Missing Authorization
Push notification for Mobile and Web app Code Analysis
SQL Query Safety
Output Escaping
Push notification for Mobile and Web app Attack Surface
WordPress Hooks 20
Maintenance & Trust
Push notification for Mobile and Web app Maintenance & Trust
Maintenance Signals
Community Trust
Push notification for Mobile and Web app Alternatives
OneSignal – Web Push Notifications
onesignal-free-web-push-notifications
Increase engagement and drive more repeat traffic to your WordPress site with push notifications. Now a WordPress VIP Gold Partner.
PushEngage – Web Push notification, WA Automation & Multi-Channel Chat Widget ( WA, Messenger, X, Telegram, TikTok & More)
pushengage
Send order updates, recover abandoned carts, and boost retention with push notifications, WhatsApp automation + multichannel Chat widget.
Web Push Notifications – Webpushr
webpushr-web-push-notifications
Fastest growing & lightweight plugin for Web Push Notifications. Add browser push notifications to your WordPress & WooCommerce site.
WP Data Access – No-Code App Builder with Tables, Forms, Charts & Maps
wp-data-access
Turn your data into WordPress apps with tables, forms, charts & maps — no code required, with optional hooks for developers. Supports 35+ languages.
AppMySite – WordPress & WooCommerce Mobile App Builder (No-Code Android & iOS App Maker)
appmysite
Turn your WordPress or WooCommerce site into a native Android & iOS app in minutes — no coding required.
Push notification for Mobile and Web app Developer Profile
1 plugin · 500 total installs
How We Detect Push notification for Mobile and Web app
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/push-notification-mobile-and-web-app/assets/css/admin.css/wp-content/plugins/push-notification-mobile-and-web-app/assets/css/frontend.css/wp-content/plugins/push-notification-mobile-and-web-app/assets/js/admin.js/wp-content/plugins/push-notification-mobile-and-web-app/assets/js/frontend.js/wp-content/plugins/push-notification-mobile-and-web-app/assets/js/admin.js/wp-content/plugins/push-notification-mobile-and-web-app/assets/js/frontend.jspush-notification-mobile-and-web-app/assets/css/admin.css?ver=push-notification-mobile-and-web-app/assets/css/frontend.css?ver=push-notification-mobile-and-web-app/assets/js/admin.js?ver=push-notification-mobile-and-web-app/assets/js/frontend.js?ver=HTML / DOM Fingerprints
push-notify-admin-menudata-push-notifypushNotifyData/wp-json/push-notify/v1