
Push World Security & Risk Analysis
wordpress.org/plugins/push-worldThis plugin help send personal and mass push notifications. It also can return customers to abandoned WooCommerce cart through push notifications.
Is Push World Safe to Use in 2026?
Generally Safe
Score 100/100Push World has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "push-world" v2.0.2 plugin presents a significant security risk due to its exposed attack surface. All five identified AJAX handlers lack authentication checks, meaning any unauthenticated user could potentially trigger these functions. This is a critical oversight that bypasses WordPress's built-in security mechanisms.
While the plugin demonstrates some good practices, such as the absence of dangerous functions and a lack of critical or high severity taint flows, these strengths are overshadowed by the critical lack of authorization on its AJAX endpoints. The presence of nonce checks on only one AJAX handler further exacerbates this risk. Although there is no known vulnerability history, the current code analysis reveals a high likelihood of exploitable vulnerabilities due to the unprotected entry points. The plugin's file operations and external HTTP requests, while not inherently risky, could become vectors for exploitation if combined with the unauthenticated AJAX handlers.
In conclusion, while the plugin doesn't appear to have a history of vulnerabilities and avoids some common pitfalls, the lack of authentication on all its AJAX handlers is a severe weakness. This makes it highly susceptible to unauthorized actions and requires immediate attention. The development team should prioritize implementing proper authentication and authorization checks on all AJAX handlers to mitigate these risks.
Key Concerns
- 5 AJAX handlers without auth checks
- Only 1 nonce check on AJAX handlers
- SQL queries: 50% using prepared statements
- Output escaping: 64% properly escaped
Push World Security Vulnerabilities
Push World Code Analysis
SQL Query Safety
Output Escaping
Push World Attack Surface
AJAX Handlers 5
WordPress Hooks 16
Scheduled Events 1
Maintenance & Trust
Push World Maintenance & Trust
Maintenance Signals
Community Trust
Push World Alternatives
PushCrew
pushcrew
With PushCrew, any website on the web can get up and running with browser push notifications in less than a minute.
Web Push Notifications by Aimtell
aimtell-web-push-notifications
Aimtell enables users to re-engage their website visitors with highly targeted mobile & desktop web push notifications.
EP Pushcrew (now VWO Engage)
ep-pushcrew-now-vwo-engage
With EP PushCrew, You can add PushCrew (now VWO Engage) browser push notifications to your website in less than a minute.
informvisitors
informvisitors
With informvisitors, you can start sending browser push notifications to your clients in less than a minute.Just install the plugin and enjoy.
PopNotifi
popnotifi
The Push Notifications Revolution by PopNotifi
Push World Developer Profile
1 plugin · 10 total installs
How We Detect Push World
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/push-world/css/app.css/wp-content/plugins/push-world/js/app.js/wp-content/plugins/push-world/js/app.jspush-world/style.css?ver=push-world/script.js?ver=HTML / DOM Fingerprints
pw-check-filepw-file__successpw-file__errorpw-btn__checkjs-push-testpw-enable-woocommercejs-tabsb-tabs+6 more<!-- Close tab: Regular fields --><!-- Checkbox -->data-checkdata-forSunrise7