Pushdy – Web Push Notifications Security & Risk Analysis

wordpress.org/plugins/pushdy-notifications

Increase engagement and drive more repeat traffic to your WordPress site with desktop push notifications. Now supporting Chrome, Firefox, and Safari.

0 active installs v1.0.0 PHP + WP 3.8+ Updated Oct 24, 2019
chromefirefoxpushpush-notificationssafari
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Pushdy – Web Push Notifications Safe to Use in 2026?

Generally Safe

Score 85/100

Pushdy – Web Push Notifications has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The pushdy-notifications plugin v1.0.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for SQL queries and not bundling external libraries, which can sometimes introduce vulnerabilities. The absence of known CVEs and common vulnerability types in its history is also a strong indicator of a relatively secure development past. However, significant concerns arise from the static analysis. The plugin has a total of one entry point, an AJAX handler, which critically lacks authentication checks. This unprotected entry point represents a direct pathway for unauthenticated attackers to interact with the plugin's functionality, potentially leading to unauthorized actions or information disclosure. While taint analysis shows no critical or high-severity unsanitized flows, the presence of an unprotected AJAX handler is a severe weakness that could be exploited if it performs sensitive operations.

Key Concerns

  • Unprotected AJAX handler
  • Low percentage of properly escaped output
Vulnerabilities
None known

Pushdy – Web Push Notifications Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Pushdy – Web Push Notifications Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
20
22 escaped
Nonce Checks
2
Capability Checks
3
File Operations
0
External Requests
5
Bundled Libraries
0

Output Escaping

52% escaped42 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<pushdy-admin> (pushdy-admin.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Pushdy – Web Push Notifications Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_has_metadatapushdy-admin.php:24
WordPress Hooks 19
actionadmin_enqueue_scriptspushdy-admin.php:13
actionwoocommerce_add_to_cartpushdy-admin.php:60
actionwoocommerce_cart_item_removedpushdy-admin.php:61
actionwoocommerce_after_cart_item_quantity_updatepushdy-admin.php:62
actionwp_footerpushdy-admin.php:63
actionadmin_menupushdy-admin.php:218
actionadmin_initpushdy-admin.php:221
actionsave_postpushdy-admin.php:224
actiontransition_post_statuspushdy-admin.php:225
actionadmin_enqueue_scriptspushdy-admin.php:226
actionadmin_noticespushdy-admin.php:311
actionadmin_enqueue_scriptspushdy-admin.php:541
actionadmin_noticespushdy-admin.php:561
actionadmin_noticespushdy-admin.php:573
filteradmin_footer_textpushdy-admin.php:579
actionwp_headpushdy-public.php:67
actionwidgets_initpushdy-widget.php:46
actioninitpushdy.php:29
actioninitpushdy.php:30
Maintenance & Trust

Pushdy – Web Push Notifications Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedOct 24, 2019
PHP min version
Downloads919

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Pushdy – Web Push Notifications Developer Profile

pushdytech

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Pushdy – Web Push Notifications

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/pushdy-notifications/notice.js
Script Paths
notice.js
Version Parameters
notice.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- Google tag (gtag.js) -->
Data Attributes
data-ga-event-actiondata-ga-event-categorydata-ga-event-labeldata-ga-event-value
JS Globals
ajax_objectpa_woo_product_info
REST Endpoints
/wp-json/pushdy/v1/settings
FAQ

Frequently Asked Questions about Pushdy – Web Push Notifications