Pushbullet Notifications for WordPress Security & Risk Analysis

wordpress.org/plugins/pushbullet-notification

Pushbullet Notifications allows your WordPress site to send push notifications straight to your Android and iOS device.

10 active installs v1.3.6 PHP + WP 3.0+ Updated May 19, 2014
androidiosmobilepush-notificationspushbullet-notifications
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Pushbullet Notifications for WordPress Safe to Use in 2026?

Generally Safe

Score 85/100

Pushbullet Notifications for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The 'pushbullet-notification' plugin v1.3.6 exhibits a generally strong security posture with no known vulnerabilities or critical issues identified in taint analysis. The absence of dangerous functions, SQL injection vulnerabilities due to prepared statements, and file operations are significant strengths. Furthermore, the plugin correctly implements a nonce check and makes external HTTP requests, which are typical for notification services. However, a notable concern is the low percentage of properly escaped output (12%). This indicates a risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is directly outputted into the page without adequate sanitization. While the attack surface is minimal and appears to have proper checks, the output escaping deficiency presents a tangible risk that requires attention.

Given the lack of historical vulnerabilities and the presence of good practices like prepared statements and nonce checks, the plugin's overall security is good. The primary weakness lies in the output escaping, which, if exploited, could lead to XSS. The taint analysis showing unsanitized paths, though not critical, aligns with this concern and suggests that some data flow might not be handled with the utmost care, potentially leading to output vulnerabilities. Addressing the output escaping issue should be a priority to further harden the plugin's security.

Key Concerns

  • Low percentage of properly escaped output
  • Unsanitized paths in taint analysis
Vulnerabilities
None known

Pushbullet Notifications for WordPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Pushbullet Notifications for WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
57
8 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

12% escaped65 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

3 flows2 with unsanitized paths
fnpn_display_sysinfo (includes\admin\admin-pages.php:284)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Pushbullet Notifications for WordPress Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 15
actioninitpushbullet-notifications.php:24
actioncron_schedulespushbullet-notifications.php:25
actioninitpushbullet-notifications.php:26
actionadmin_enqueue_scriptspushbullet-notifications.php:27
actionuser_registerpushbullet-notifications.php:30
actionwp_loginpushbullet-notifications.php:34
actionxmlrpc_publish_postpushbullet-notifications.php:39
actioncomment_postpushbullet-notifications.php:43
actionlostpassword_postpushbullet-notifications.php:47
actiontransition_post_statuspushbullet-notifications.php:51
actionadmin_noticespushbullet-notifications.php:59
actionadmin_initpushbullet-notifications.php:62
actionadmin_menupushbullet-notifications.php:63
filterplugin_action_linkspushbullet-notifications.php:64
actionfnpn_plugin_update_checkpushbullet-notifications.php:117

Scheduled Events 1

fnpn_plugin_update_check
Maintenance & Trust

Pushbullet Notifications for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested3.9.40
Last updatedMay 19, 2014
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

Pushbullet Notifications for WordPress Developer Profile

ploufs

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Pushbullet Notifications for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/pushbullet-notification/includes/scripts/fnpn_custom.js
Script Paths
/wp-content/plugins/pushbullet-notification/includes/scripts/fnpn_custom.js
Version Parameters
fnpn_custom.js?ver=

HTML / DOM Fingerprints

JS Globals
fnpn_core_custom_js
FAQ

Frequently Asked Questions about Pushbullet Notifications for WordPress