Pushe Web Push Notification Security & Risk Analysis

wordpress.org/plugins/pushe-webpush

Pushe.co's official web push notification plugin. Pushe.co console is only available for Farsi language (English version will come soon).

40 active installs v0.5.0 PHP 5.2.4+ WP 3.5+ Updated Jun 28, 2021
engagementnotificationpushpush-notificationsweb-push
63
C · Use Caution
CVEs total1
Unpatched1
Last CVESep 5, 2025
Download
Safety Verdict

Is Pushe Web Push Notification Safe to Use in 2026?

Use With Caution

Score 63/100

Pushe Web Push Notification has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Sep 5, 2025Updated 4yr ago
Risk Assessment

The plugin 'pushe-webpush' v0.5.0 exhibits a mixed security posture. While the static analysis reveals no detected attack surface and a complete absence of dangerous functions and raw SQL queries, indicating good practices in these areas, significant concerns arise from other metrics. The low percentage of properly escaped output (17%) is a major red flag, suggesting a high likelihood of cross-site scripting vulnerabilities. Furthermore, the complete lack of nonce and capability checks, combined with no authorization checks on any identified entry points (although the attack surface is currently reported as zero), raises questions about its robustness against unauthorized access or manipulation if entry points were to be discovered or added.

The vulnerability history is particularly worrying, with one unpatched medium severity CVE related to Cross-site Scripting. This, coupled with the fact that the last vulnerability was very recent (2025-09-05), strongly indicates a pattern of insecure coding practices that have led to exploitable flaws. The presence of this unpatched vulnerability, despite the absence of identified critical or high severity issues in the static analysis, means a known risk is present and actively exploitable. In conclusion, while the plugin appears to have some secure foundational elements like prepared SQL statements, the pervasive risk of XSS due to poor output escaping and the existence of an unpatched medium severity vulnerability present a significant security concern for users.

Key Concerns

  • Unpatched Medium Severity CVE
  • Low output escaping percentage (17%)
  • No nonce checks
  • No capability checks
  • No authorization checks on entry points
Vulnerabilities
1 published

Pushe Web Push Notification Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-58873medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Pushe Web Push Notification <= 0.5.0 - Authenticated (Administrator+) Stored Cross-Site Scripting

Sep 5, 2025Unpatched
Version History

Pushe Web Push Notification Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

Pushe Web Push Notification Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

17% escaped6 total outputs
Attack Surface

Pushe Web Push Notification Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_menuinc\api\SettingsApi.php:21
actionadmin_initinc\api\SettingsApi.php:25
actionadmin_enqueue_scriptsinc\base\Enqueue.php:14
actionwp_footerinc\base\WebpushScripts.php:37
Maintenance & Trust

Pushe Web Push Notification Maintenance & Trust

Maintenance Signals

WordPress version tested5.3.21
Last updatedJun 28, 2021
PHP min version5.2.4
Downloads3K

Community Trust

Rating88/100
Number of ratings7
Active installs40
Developer Profile

Pushe Web Push Notification Developer Profile

pusheco

1 plugin · 40 total installs

68
trust score
Avg Security Score
63/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Pushe Web Push Notification

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/pushe-webpush/assets/pushe-webpush.css/wp-content/plugins/pushe-webpush/assets/pushe-webpush.js
Script Paths
https://static.pushe.co/pusheweb.js

HTML / DOM Fingerprints

JS Globals
Pushe
FAQ

Frequently Asked Questions about Pushe Web Push Notification