
Onsite Messaging by PushAlert – Exit Intent Popups, Email Optins, Discount Overlays Security & Risk Analysis
wordpress.org/plugins/pushalert-onsite-messagingA plugin by PushAlert to enable onsite messaging for your WordPress and WooCommerce Store to build email list, boost sales and recover abandoned cart.
Is Onsite Messaging by PushAlert – Exit Intent Popups, Email Optins, Discount Overlays Safe to Use in 2026?
Generally Safe
Score 100/100Onsite Messaging by PushAlert – Exit Intent Popups, Email Optins, Discount Overlays has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The pushalert-onsite-messaging plugin version 1.2.0 exhibits a strong security posture based on the provided static analysis. The absence of any identified entry points (AJAX handlers, REST API routes, shortcodes, cron events) significantly limits the plugin's attack surface. Furthermore, the code demonstrates good security practices by using prepared statements for all SQL queries, which prevents SQL injection vulnerabilities. The high percentage of properly escaped output (82%) is also a positive indicator, though the remaining 18% could potentially be a vector for cross-site scripting (XSS) if user-controlled data is involved in those unescaped outputs.
The vulnerability history is completely clean, with no recorded CVEs. This indicates a consistent track record of secure development or prompt patching of any past issues. The taint analysis revealing no unsanitized paths further reinforces the impression of well-handled data flows within the plugin. The presence of a nonce check is a good practice for preventing CSRF attacks on any potential actions that might exist, although the lack of identified entry points makes its immediate application less critical. However, the complete absence of capability checks is a notable concern, as it means that any actions or functionalities within the plugin might be accessible to users who should not have such permissions, especially if hidden entry points were to be discovered or if future updates introduce them without proper authorization.
Overall, the plugin appears to be developed with security in mind, particularly regarding common web vulnerabilities like SQL injection and XSS. Its minimal attack surface and lack of historical vulnerabilities are significant strengths. The primary area for improvement lies in the implementation of capability checks to ensure granular access control. While the current findings are positive, it's important to remember that static analysis is not exhaustive and might miss certain dynamic vulnerabilities or logic flaws.
Key Concerns
- No capability checks implemented
- 18% of output not properly escaped
Onsite Messaging by PushAlert – Exit Intent Popups, Email Optins, Discount Overlays Security Vulnerabilities
Onsite Messaging by PushAlert – Exit Intent Popups, Email Optins, Discount Overlays Code Analysis
Output Escaping
Onsite Messaging by PushAlert – Exit Intent Popups, Email Optins, Discount Overlays Attack Surface
WordPress Hooks 8
Maintenance & Trust
Onsite Messaging by PushAlert – Exit Intent Popups, Email Optins, Discount Overlays Maintenance & Trust
Maintenance Signals
Community Trust
Onsite Messaging by PushAlert – Exit Intent Popups, Email Optins, Discount Overlays Alternatives
Brave Popup Builder – Popup, Optins, Lead Generation, Survey & Interactive Content
brave-popup-builder
The best drag-and-drop Popup Builder for WordPress. Create Popups, exit-intent popups, slide-ins, and lead generation forms & Woocommerce popups i …
WebToffee eCommerce Marketing Automation – Email marketing, Popups, Email customizer
decorator-woocommerce-email-customizer
Create and send marketing emails and campaigns. Enable email automations, Popups, spin-a-wheel, sign-up forms, and more. Customize WooCommerce emails.
Upsell Funnel Builder for WooCommerce – Create Upsells, Cross-Sells, Order Bumps, Frequently Bought, and Popups.
upsell-order-bump-offer-for-woocommerce
Upsell Funnel Builder lets you create WooCommerce Upsells, Order Bumps, One Click upsell, Cross-Sells, Frequently Bought, and Popups.
Abandoned Cart Reports For WooCommerce
wc-abandoned-carts-by-small-fish-analytics
A simple plugin to see how many carts and which products your customers are abandoning
YITH WooCommerce Popup
yith-woocommerce-popup
Create and customize your popup windows using templates carefully designed by YITH.
Onsite Messaging by PushAlert – Exit Intent Popups, Email Optins, Discount Overlays Developer Profile
2 plugins · 1K total installs
How We Detect Onsite Messaging by PushAlert – Exit Intent Popups, Email Optins, Discount Overlays
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pushalert-onsite-messaging/style.css/wp-content/plugins/pushalert-onsite-messaging/js/pa-onsite-messaging.jspushalert-onsite-messaging/style.css?ver=pa-onsite-messaging.js?ver=HTML / DOM Fingerprints
wc-rating-link<!-- Onsite Messaging 1.2.0 -->data-ratedonsitemessagingbypa