Push notification for Mobile and Web app Security & Risk Analysis

wordpress.org/plugins/push-notification-mobile-and-web-app

Push notification for Android, iOS and the Web

500 active installs v2.0.4 PHP 7.4+ WP 5.8+ Updated Dec 6, 2025
android-notificationsapp-builderfirebase-messagesios-notificationspush-notification
99
A · Safe
CVEs total1
Unpatched0
Last CVEMay 16, 2025
Safety Verdict

Is Push notification for Mobile and Web app Safe to Use in 2026?

Generally Safe

Score 99/100

Push notification for Mobile and Web app has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: May 16, 2025Updated 3mo ago
Risk Assessment

The plugin "push-notification-mobile-and-web-app" v2.0.4 exhibits a generally positive security posture with good practices in place. The static analysis reveals no critical or high-severity taint flows, and a very high percentage of SQL queries are prepared, which significantly mitigates SQL injection risks. File operations are absent, reducing the attack surface related to arbitrary file writes. However, there are a few areas for concern. The lack of nonce checks across all entry points is a significant weakness, potentially leaving the application vulnerable to Cross-Site Request Forgery (CSRF) attacks if any unprotected AJAX handlers were present. Additionally, the output escaping is only 40% proper, indicating potential for Cross-Site Scripting (XSS) vulnerabilities in rendered content. The vulnerability history shows one past medium-severity vulnerability, which was a "Missing Authorization" issue. While currently unpatched vulnerabilities are zero, the historical pattern of authorization issues, coupled with the absence of robust authorization checks in the static analysis (only one capability check is noted), suggests a recurring risk that requires attention. Overall, while the plugin avoids some common pitfalls like raw SQL and unpatched critical vulnerabilities, the lack of comprehensive authorization and output sanitization, along with the absence of nonces, presents tangible risks that should be addressed.

Key Concerns

  • No nonce checks on entry points
  • Low percentage of properly escaped output
  • Only 1 capability check found
  • 1 past medium severity CVE (Missing Authorization)
Vulnerabilities
1

Push notification for Mobile and Web app Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-48127medium · 5.3Missing Authorization

Push notification for Mobile and Web app <= 2.0.3 - Missing Authorization

May 16, 2025 Patched in 2.0.4 (208d)
Code Analysis
Analyzed Mar 16, 2026

Push notification for Mobile and Web app Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
30 prepared
Unescaped Output
12
8 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
4
Bundled Libraries
0

SQL Query Safety

97% prepared31 total queries

Output Escaping

40% escaped20 total outputs
Attack Surface

Push notification for Mobile and Web app Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 20
actionmessages_message_sentincludes\Actions\BbAction.php:23
actionbetter_messages_message_sentincludes\Actions\BbAction.php:25
actionbp_activity_posted_updateincludes\Actions\BbAction.php:27
actionbp_activity_groups_posted_updateincludes\Actions\BbAction.php:28
actionfriends_friendship_acceptedincludes\Actions\BbAction.php:29
actionfriends_friendship_requestedincludes\Actions\BbAction.php:30
actiongroups_send_invitesincludes\Actions\BbAction.php:31
actionafter_wcfm_notificationincludes\Actions\WcfmAction.php:20
actionwoocommerce_order_status_changedincludes\Actions\WooAction.php:22
actiontransition_post_statusincludes\Actions\WooAction.php:23
actioncomment_postincludes\Actions\WpAction.php:22
actionsave_postincludes\Actions\WpAction.php:34
actionadmin_menuincludes\Admin\Menu.php:38
filterrest_authentication_errorsincludes\Api\AppBuilderKey.php:87
actionrest_api_initincludes\Api.php:41
actionwp_enqueue_scriptsincludes\Frontend.php:22
actioninitincludes\PostTypes.php:28
actioninitincludes\PostTypes.php:29
actionplugins_loadedpush-notify.php:179
actioninitpush-notify.php:180
Maintenance & Trust

Push notification for Mobile and Web app Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedDec 6, 2025
PHP min version7.4
Downloads16K

Community Trust

Rating0/100
Number of ratings0
Active installs500
Developer Profile

Push notification for Mobile and Web app Developer Profile

App Cheap

1 plugin · 500 total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
208 days
View full developer profile
Detection Fingerprints

How We Detect Push notification for Mobile and Web app

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/push-notification-mobile-and-web-app/assets/css/admin.css/wp-content/plugins/push-notification-mobile-and-web-app/assets/css/frontend.css/wp-content/plugins/push-notification-mobile-and-web-app/assets/js/admin.js/wp-content/plugins/push-notification-mobile-and-web-app/assets/js/frontend.js
Script Paths
/wp-content/plugins/push-notification-mobile-and-web-app/assets/js/admin.js/wp-content/plugins/push-notification-mobile-and-web-app/assets/js/frontend.js
Version Parameters
push-notification-mobile-and-web-app/assets/css/admin.css?ver=push-notification-mobile-and-web-app/assets/css/frontend.css?ver=push-notification-mobile-and-web-app/assets/js/admin.js?ver=push-notification-mobile-and-web-app/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
push-notify-admin-menu
Data Attributes
data-push-notify
JS Globals
pushNotifyData
REST Endpoints
/wp-json/push-notify/v1
FAQ

Frequently Asked Questions about Push notification for Mobile and Web app