
Pushbullet Notifications for WordPress Security & Risk Analysis
wordpress.org/plugins/pushbullet-notificationPushbullet Notifications allows your WordPress site to send push notifications straight to your Android and iOS device.
Is Pushbullet Notifications for WordPress Safe to Use in 2026?
Generally Safe
Score 85/100Pushbullet Notifications for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'pushbullet-notification' plugin v1.3.6 exhibits a generally strong security posture with no known vulnerabilities or critical issues identified in taint analysis. The absence of dangerous functions, SQL injection vulnerabilities due to prepared statements, and file operations are significant strengths. Furthermore, the plugin correctly implements a nonce check and makes external HTTP requests, which are typical for notification services. However, a notable concern is the low percentage of properly escaped output (12%). This indicates a risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is directly outputted into the page without adequate sanitization. While the attack surface is minimal and appears to have proper checks, the output escaping deficiency presents a tangible risk that requires attention.
Given the lack of historical vulnerabilities and the presence of good practices like prepared statements and nonce checks, the plugin's overall security is good. The primary weakness lies in the output escaping, which, if exploited, could lead to XSS. The taint analysis showing unsanitized paths, though not critical, aligns with this concern and suggests that some data flow might not be handled with the utmost care, potentially leading to output vulnerabilities. Addressing the output escaping issue should be a priority to further harden the plugin's security.
Key Concerns
- Low percentage of properly escaped output
- Unsanitized paths in taint analysis
Pushbullet Notifications for WordPress Security Vulnerabilities
Pushbullet Notifications for WordPress Code Analysis
Output Escaping
Data Flow Analysis
Pushbullet Notifications for WordPress Attack Surface
WordPress Hooks 15
Scheduled Events 1
Maintenance & Trust
Pushbullet Notifications for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Pushbullet Notifications for WordPress Alternatives
WPMobile.App
wpappninja
Android and iOS mobile application. Easy setup, free test.
Device-Based Redirect
device-based-redirect
Redirect users to your app pages in app store or play store based on their device type with custom URLs and page-specific redirects.
Mobile Smart App Banner
mobile-smart-app-banner
Transform your mobile website visitors into app users with intelligent smart app banners that boost downloads across iOS and Android devices.
WP-AppKit – Mobile apps and PWA for WordPress
wp-appkit
Important ✋: beginning with version 1.5.3, we don't support anymore native iOS app. This is a tough choice we explain here.
WP Smart Banner
wp-smartbanner
WP Smart Banner uses a small portion of the screen on a mobile website to inform and encourage users to open or install the native app.
Pushbullet Notifications for WordPress Developer Profile
1 plugin · 10 total installs
How We Detect Pushbullet Notifications for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pushbullet-notification/includes/scripts/fnpn_custom.js/wp-content/plugins/pushbullet-notification/includes/scripts/fnpn_custom.jsfnpn_custom.js?ver=HTML / DOM Fingerprints
fnpn_core_custom_js