
Pusher – Pushing mobile notification with FCM Security & Risk Analysis
wordpress.org/plugins/pusher-pushing-mobile-notifications-with-fcmIf your wordpress site has a mobile application, you can push a notification to the users of your mobile application via this plugin.
Is Pusher – Pushing mobile notification with FCM Safe to Use in 2026?
Generally Safe
Score 100/100Pusher – Pushing mobile notification with FCM has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "pusher-pushing-mobile-notifications-with-fcm" plugin version 1.0.0 exhibits a mixed security posture. On the positive side, the static analysis reveals a very limited attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events exposed without proper authentication or permission checks. Furthermore, there are no recorded historical vulnerabilities (CVEs), which suggests a history of good security practices or a lack of targeted exploitation.
However, significant concerns arise from the code signals. The plugin uses raw SQL queries without prepared statements for 100% of its database interactions. This is a critical flaw that can lead to SQL injection vulnerabilities, especially if user-supplied data is directly incorporated into these queries. Additionally, none of the output escaping is properly implemented, meaning that sensitive data displayed to users could be vulnerable to cross-site scripting (XSS) attacks. The taint analysis also flags two flows with unsanitized paths, indicating potential data leakage or manipulation vulnerabilities that require further investigation. The lack of nonce checks on any entry points, while the attack surface is currently zero, could become a problem if future updates introduce new handlers.
In conclusion, while the plugin has a clean vulnerability history and a seemingly small attack surface, the presence of unescaped output and raw SQL queries without prepared statements presents a significant security risk. The taint analysis further underscores potential vulnerabilities. It is crucial that these code-level issues are addressed to improve the plugin's overall security.
Key Concerns
- SQL queries not using prepared statements
- Output escaping not properly implemented
- Flows with unsanitized paths detected
- No nonce checks on any entry points
Pusher – Pushing mobile notification with FCM Security Vulnerabilities
Pusher – Pushing mobile notification with FCM Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Pusher – Pushing mobile notification with FCM Attack Surface
WordPress Hooks 3
Maintenance & Trust
Pusher – Pushing mobile notification with FCM Maintenance & Trust
Maintenance Signals
Community Trust
Pusher – Pushing mobile notification with FCM Alternatives
Push notification for Mobile and Web app
push-notification-mobile-and-web-app
Push notification for Android, iOS and the Web
Pushbullet Notifications for WordPress
pushbullet-notification
Pushbullet Notifications allows your WordPress site to send push notifications straight to your Android and iOS device.
Better Hints for WordPress
better-hints
Target your visitors with better notifications.
Topic-Based Push Notifications for Firebase
topic-based-push-notifications-for-firebase
Professional WordPress plugin for sending Firebase Cloud Messaging (FCM) push notifications to Android apps with advanced targeting and analytics.
WPMobile.App
wpappninja
Android and iOS mobile application. Easy setup, free test.
Pusher – Pushing mobile notification with FCM Developer Profile
3 plugins · 150 total installs
How We Detect Pusher – Pushing mobile notification with FCM
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pusher-pushing-mobile-notifications-with-fcm/includes/css/admin-style.csspusher-pushing-mobile-notifications-with-fcm/includes/css/admin-style.css?v=pusher-pushing-mobile-notifications-with-fcm/includes/css/admin-style.css?v=1.0