
PushEngage – Web Push Notifications, WooCommerce Automation & Chat Widget Security & Risk Analysis
wordpress.org/plugins/pushengageThe #1 push notification plugin for WordPress & WooCommerce. Recover abandoned carts, automate alerts, and grow subscribers — no code needed.
Is PushEngage – Web Push Notifications, WooCommerce Automation & Chat Widget Safe to Use in 2026?
Generally Safe
Score 100/100PushEngage – Web Push Notifications, WooCommerce Automation & Chat Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The Pushengage plugin v4.2.1 demonstrates some good security practices, particularly its high percentage of prepared SQL statements and properly escaped outputs. The absence of known CVEs and a clean vulnerability history are positive indicators. However, the plugin has a notable attack surface with 10 AJAX handlers, 4 of which lack authentication checks. This is a significant concern as it potentially allows unauthenticated users to trigger plugin functionality. While taint analysis did not reveal critical or high-severity issues, the presence of 5 flows with unsanitized paths warrants further investigation to ensure they do not lead to exploitable vulnerabilities in conjunction with the unprotected AJAX endpoints. The plugin also has file operations and external HTTP requests, which could be vectors if not handled securely in combination with other weaknesses.
Key Concerns
- 4 unprotected AJAX handlers present
- 5 flows with unsanitized paths detected
- File operations present (potential vector)
- External HTTP requests present (potential vector)
PushEngage – Web Push Notifications, WooCommerce Automation & Chat Widget Security Vulnerabilities
PushEngage – Web Push Notifications, WooCommerce Automation & Chat Widget Release Timeline
PushEngage – Web Push Notifications, WooCommerce Automation & Chat Widget Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
PushEngage – Web Push Notifications, WooCommerce Automation & Chat Widget Attack Surface
AJAX Handlers 10
WordPress Hooks 94
Scheduled Events 2
Maintenance & Trust
PushEngage – Web Push Notifications, WooCommerce Automation & Chat Widget Maintenance & Trust
Maintenance Signals
Community Trust
PushEngage – Web Push Notifications, WooCommerce Automation & Chat Widget Alternatives
CleverPush
cleverpush
CleverPush lets you send browser push notifications to your users in the simplest way possible.
Digital Conversion – Push Notifications & Marketing Hub
digital-conversion
Smart Web Push with unlimited subscribers, AI insights, A/B testing, automation, WooCommerce integration, and personalization.
Web Push Notifications – Webpushr
webpushr-web-push-notifications
Fastest growing & lightweight plugin for Web Push Notifications. Add browser push notifications to your WordPress & WooCommerce site.
Perfecty Push Notifications
perfecty-push-notifications
Push Notifications that are self-hosted, you don't need API keys to integrate with external Push Notifications providers that will charge you lat …
Gravitec.net – Web Push Notifications
gravitec-net-web-push-notifications
Easy-to-use and smart push notifications for your website. Increase subscriptions and repeat visits with minimal effort.
PushEngage – Web Push Notifications, WooCommerce Automation & Chat Widget Developer Profile
94 plugins · 23.5M total installs
How We Detect PushEngage – Web Push Notifications, WooCommerce Automation & Chat Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pushengage/assets/css/admin-menu.css/wp-content/plugins/pushengage/assets/img/pushengage.svgpushengage/assets/css/admin-menu.css?ver=HTML / DOM Fingerprints
pushengage-main-logo<!-- START PushEngage --><!-- END PushEngage --><!-- This file is part of the PushEngage plugin. -->data-pushengage-site-idpushengage_settings/wp-json/pushengage/v1/settings/wp-json/pushengage/v1/site_settings