
PushAlert – Web Push Notifications for WordPress and WooCommerce Security & Risk Analysis
wordpress.org/plugins/pushalert-web-push-notificationsA plugin by PushAlert to enable automated Push Notifications for your WordPress website and WooCommerce Store to increase traffic and sales.
Is PushAlert – Web Push Notifications for WordPress and WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100PushAlert – Web Push Notifications for WordPress and WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "pushalert-web-push-notifications" plugin v2.9.0 exhibits a generally good security posture based on the static analysis. The absence of SQL injection vulnerabilities due to prepared statements, a limited attack surface with only one AJAX handler (which is reportedly protected), and the lack of known CVEs are positive indicators. The plugin also demonstrates good practice by performing nonce checks on its entry points.
However, there are areas for improvement. The output escaping is only properly handled in 45% of cases, indicating a potential risk of cross-site scripting (XSS) vulnerabilities. While no critical or high severity taint flows were identified, the presence of one flow with unsanitized paths warrants attention as it could lead to unexpected behavior or expose sensitive information if exploited. The limited capability checks also suggest that authorization might not be as robust as it could be for all actions.
Overall, the plugin appears to be relatively secure, especially given its clean vulnerability history. The primary concerns revolve around the potential for XSS due to insufficient output escaping and the single identified unsanitized path, which should be investigated and remediated to further strengthen its security.
Key Concerns
- Insufficient output escaping
- Flow with unsanitized paths
- No capability checks on entry points
PushAlert – Web Push Notifications for WordPress and WooCommerce Security Vulnerabilities
PushAlert – Web Push Notifications for WordPress and WooCommerce Code Analysis
Output Escaping
Data Flow Analysis
PushAlert – Web Push Notifications for WordPress and WooCommerce Attack Surface
AJAX Handlers 1
WordPress Hooks 25
Maintenance & Trust
PushAlert – Web Push Notifications for WordPress and WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
PushAlert – Web Push Notifications for WordPress and WooCommerce Alternatives
Feedify – Web Push Notifications
push-notification-by-feedify
Engage your customer with Web Push Notifications. Send them personalised messages even when they aren't on your website.
DigitalPUSH notifications
digitalpush
This plugin allows you to to implement push notifications with your WordPress blog.
informvisitors
informvisitors
With informvisitors, you can start sending browser push notifications to your clients in less than a minute.Just install the plugin and enjoy.
Notificare
notificare-website-push
Smart push notifications for WordPress websites.
WorldShaking Web Push Notifications
push-notification-worldshaking
Increase engagement and drive more repeat traffic to your WordPress site with desktop push notifications. Now supporting Chrome, Firefox, and Safari.
PushAlert – Web Push Notifications for WordPress and WooCommerce Developer Profile
2 plugins · 1K total installs
How We Detect PushAlert – Web Push Notifications for WordPress and WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pushalert-web-push-notifications/style.css/wp-content/plugins/pushalert-web-push-notifications/javascript.js/wp-content/plugins/pushalert-web-push-notifications/javascript.jspushalert-web-push-notifications/style.css?ver=pushalert-web-push-notifications/javascript.js?ver=HTML / DOM Fingerprints
data-pushalert-enablePushAlertpa_vars/wp-json/pushalert/v1/associate