
Pushe Web Push Notification Security & Risk Analysis
wordpress.org/plugins/pushe-webpushPushe.co's official web push notification plugin. Pushe.co console is only available for Farsi language (English version will come soon).
Is Pushe Web Push Notification Safe to Use in 2026?
Use With Caution
Score 63/100Pushe Web Push Notification has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The plugin 'pushe-webpush' v0.5.0 exhibits a mixed security posture. While the static analysis reveals no detected attack surface and a complete absence of dangerous functions and raw SQL queries, indicating good practices in these areas, significant concerns arise from other metrics. The low percentage of properly escaped output (17%) is a major red flag, suggesting a high likelihood of cross-site scripting vulnerabilities. Furthermore, the complete lack of nonce and capability checks, combined with no authorization checks on any identified entry points (although the attack surface is currently reported as zero), raises questions about its robustness against unauthorized access or manipulation if entry points were to be discovered or added.
The vulnerability history is particularly worrying, with one unpatched medium severity CVE related to Cross-site Scripting. This, coupled with the fact that the last vulnerability was very recent (2025-09-05), strongly indicates a pattern of insecure coding practices that have led to exploitable flaws. The presence of this unpatched vulnerability, despite the absence of identified critical or high severity issues in the static analysis, means a known risk is present and actively exploitable. In conclusion, while the plugin appears to have some secure foundational elements like prepared SQL statements, the pervasive risk of XSS due to poor output escaping and the existence of an unpatched medium severity vulnerability present a significant security concern for users.
Key Concerns
- Unpatched Medium Severity CVE
- Low output escaping percentage (17%)
- No nonce checks
- No capability checks
- No authorization checks on entry points
Pushe Web Push Notification Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Pushe Web Push Notification <= 0.5.0 - Authenticated (Administrator+) Stored Cross-Site Scripting
Pushe Web Push Notification Release Timeline
Pushe Web Push Notification Code Analysis
Output Escaping
Pushe Web Push Notification Attack Surface
WordPress Hooks 4
Maintenance & Trust
Pushe Web Push Notification Maintenance & Trust
Maintenance Signals
Community Trust
Pushe Web Push Notification Alternatives
Perfecty Push Notifications
perfecty-push-notifications
Push Notifications that are self-hosted, you don't need API keys to integrate with external Push Notifications providers that will charge you lat …
Adwised Web Push Notification
adwised
adwised.com's official web push notification plugin. adwised.com console is only available for Farsi language (English version will come soon).
PushRelay – Push Notifications
pushrelay
Send web push notifications to bring visitors back to your WordPress site.
PushEngage – Web Push Notifications, WooCommerce Automation & Chat Widget
pushengage
The #1 push notification plugin for WordPress & WooCommerce. Recover abandoned carts, automate alerts, and grow subscribers — no code needed.
Web Push Notifications – Webpushr
webpushr-web-push-notifications
Fastest growing & lightweight plugin for Web Push Notifications. Add browser push notifications to your WordPress & WooCommerce site.
Pushe Web Push Notification Developer Profile
1 plugin · 40 total installs
How We Detect Pushe Web Push Notification
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pushe-webpush/assets/pushe-webpush.css/wp-content/plugins/pushe-webpush/assets/pushe-webpush.jshttps://static.pushe.co/pusheweb.jsHTML / DOM Fingerprints
Pushe