Pushatomic Security & Risk Analysis

wordpress.org/plugins/pushatomic

Monetize your website with push notifications

10 active installs v1.0.15 PHP 5.3+ WP 3.3.1+ Updated May 30, 2024
adsadsensemonetizationnotificationpush
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Pushatomic Safe to Use in 2026?

Generally Safe

Score 92/100

Pushatomic has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "pushatomic" plugin v1.0.15 exhibits a generally good security posture based on the provided static analysis. A significant strength is the absence of direct SQL injection vulnerabilities, as all identified SQL queries utilize prepared statements. Furthermore, the plugin demonstrates awareness of security best practices by including nonce checks and having a minimal attack surface with only one AJAX handler, which is reported as unprotected. The lack of known CVEs and a clean vulnerability history further contributes to a positive assessment. However, a notable concern is the low percentage of properly escaped output. With only 20% of outputs being properly escaped, there is a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. This means that data displayed to users, if not carefully handled by the WordPress core or other plugins, could potentially be manipulated to execute malicious scripts.

Key Concerns

  • Low percentage of properly escaped output
  • Unprotected AJAX handler
Vulnerabilities
None known

Pushatomic Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Pushatomic Release Timeline

v1.0.15Current
v1.0.14
v1.0.13
v1.0.12
v1.0.11
v1.0.10
v1.0.9
v1.0.8
v1.0.7
v1.0.6
v1.0.5
Code Analysis
Analyzed Apr 16, 2026

Pushatomic Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
82
21 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

20% escaped103 total outputs
Attack Surface

Pushatomic Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_pushatomic_save_settingspushatomic.php:35
WordPress Hooks 3
actioninitpushatomic.php:24
actionwp_footerpushatomic.php:25
actionadmin_menupushatomic.php:34
Maintenance & Trust

Pushatomic Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedMay 30, 2024
PHP min version5.3
Downloads2K

Community Trust

Rating88/100
Number of ratings7
Active installs10
Developer Profile

Pushatomic Developer Profile

hullcode

3 plugins · 1K total installs

86
trust score
Avg Security Score
97/100
Avg Patch Time
55 days
View full developer profile
Detection Fingerprints

How We Detect Pushatomic

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/pushatomic/pushatomic.css/wp-content/plugins/pushatomic/pushatomic.js
Script Paths
/wp-content/plugins/pushatomic/pushatomic.js
Version Parameters
pushatomic.css?ver=pushatomic.js?ver=

HTML / DOM Fingerprints

CSS Classes
pushatomic-container
Data Attributes
data-pushatomic-iddata-pushatomic-sw
JS Globals
pushatomic_settings
FAQ

Frequently Asked Questions about Pushatomic