
PushEngage – Web Push notification, WA Automation & Multi-Channel Chat Widget ( WA, Messenger, X, Telegram, TikTok & More) Security & Risk Analysis
wordpress.org/plugins/pushengageSend order updates, recover abandoned carts, and boost retention with push notifications, WhatsApp automation + multichannel Chat widget.
Is PushEngage – Web Push notification, WA Automation & Multi-Channel Chat Widget ( WA, Messenger, X, Telegram, TikTok & More) Safe to Use in 2026?
Generally Safe
Score 100/100PushEngage – Web Push notification, WA Automation & Multi-Channel Chat Widget ( WA, Messenger, X, Telegram, TikTok & More) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The Pushengage plugin v4.2.1 demonstrates some good security practices, particularly its high percentage of prepared SQL statements and properly escaped outputs. The absence of known CVEs and a clean vulnerability history are positive indicators. However, the plugin has a notable attack surface with 10 AJAX handlers, 4 of which lack authentication checks. This is a significant concern as it potentially allows unauthenticated users to trigger plugin functionality. While taint analysis did not reveal critical or high-severity issues, the presence of 5 flows with unsanitized paths warrants further investigation to ensure they do not lead to exploitable vulnerabilities in conjunction with the unprotected AJAX endpoints. The plugin also has file operations and external HTTP requests, which could be vectors if not handled securely in combination with other weaknesses.
Key Concerns
- 4 unprotected AJAX handlers present
- 5 flows with unsanitized paths detected
- File operations present (potential vector)
- External HTTP requests present (potential vector)
PushEngage – Web Push notification, WA Automation & Multi-Channel Chat Widget ( WA, Messenger, X, Telegram, TikTok & More) Security Vulnerabilities
PushEngage – Web Push notification, WA Automation & Multi-Channel Chat Widget ( WA, Messenger, X, Telegram, TikTok & More) Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
PushEngage – Web Push notification, WA Automation & Multi-Channel Chat Widget ( WA, Messenger, X, Telegram, TikTok & More) Attack Surface
AJAX Handlers 10
WordPress Hooks 94
Scheduled Events 2
Maintenance & Trust
PushEngage – Web Push notification, WA Automation & Multi-Channel Chat Widget ( WA, Messenger, X, Telegram, TikTok & More) Maintenance & Trust
Maintenance Signals
Community Trust
PushEngage – Web Push notification, WA Automation & Multi-Channel Chat Widget ( WA, Messenger, X, Telegram, TikTok & More) Alternatives
Web Push Notifications – Webpushr
webpushr-web-push-notifications
Fastest growing & lightweight plugin for Web Push Notifications. Add browser push notifications to your WordPress & WooCommerce site.
Perfecty Push Notifications
perfecty-push-notifications
Push Notifications that are self-hosted, you don't need API keys to integrate with external Push Notifications providers that will charge you lat …
Gravitec.net – Web Push Notifications
gravitec-net-web-push-notifications
Easy-to-use and smart push notifications for your website. Increase subscriptions and repeat visits with minimal effort.
iZooto – Web Push Notifications
izooto-web-push
Engage your audience and drive repeat traffic by delivering relevant and personalized push notifications - across web browsers, Android, iOS and Messe …
Pushly
pushly
Take user engagement to a whole new level with an easy-to-use platform to engage audiences with targeted content after they leave your site.
PushEngage – Web Push notification, WA Automation & Multi-Channel Chat Widget ( WA, Messenger, X, Telegram, TikTok & More) Developer Profile
94 plugins · 23.5M total installs
How We Detect PushEngage – Web Push notification, WA Automation & Multi-Channel Chat Widget ( WA, Messenger, X, Telegram, TikTok & More)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pushengage/assets/css/admin-menu.css/wp-content/plugins/pushengage/assets/img/pushengage.svgpushengage/assets/css/admin-menu.css?ver=HTML / DOM Fingerprints
pushengage-main-logo<!-- START PushEngage --><!-- END PushEngage --><!-- This file is part of the PushEngage plugin. -->data-pushengage-site-idpushengage_settings/wp-json/pushengage/v1/settings/wp-json/pushengage/v1/site_settings