
Pushly Security & Risk Analysis
wordpress.org/plugins/pushlyTake user engagement to a whole new level with an easy-to-use platform to engage audiences with targeted content after they leave your site.
Is Pushly Safe to Use in 2026?
Generally Safe
Score 100/100Pushly has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The Pushly v2.1.9 plugin exhibits a generally strong security posture, with no known vulnerabilities or CVEs recorded. The static analysis reveals a small attack surface, with all identified entry points (REST API routes) including permission callbacks. The plugin also demonstrates good practices by exclusively using prepared statements for SQL queries. However, the presence of the `unserialize` function, which is known to be dangerous if used with untrusted input, is a significant concern. Furthermore, only 65% of output is properly escaped, indicating a potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled with sufficient care before being displayed. The lack of nonce checks on any potential AJAX handlers, although currently no AJAX handlers are present, could become a risk if new ones are added without proper security measures. The plugin does not bundle external libraries, which is a positive aspect. The absence of taint analysis results is noted but doesn't necessarily indicate a lack of issues, as this functionality may not have been comprehensively applied or the results were null.
Key Concerns
- Dangerous function used (unserialize)
- Insufficient output escaping (35% unescaped)
- No nonce checks found
Pushly Security Vulnerabilities
Pushly Code Analysis
Dangerous Functions Found
Output Escaping
Pushly Attack Surface
REST API Routes 1
WordPress Hooks 20
Maintenance & Trust
Pushly Maintenance & Trust
Maintenance Signals
Community Trust
Pushly Alternatives
PushEngage – Web Push notification, WA Automation & Multi-Channel Chat Widget ( WA, Messenger, X, Telegram, TikTok & More)
pushengage
Send order updates, recover abandoned carts, and boost retention with push notifications, WhatsApp automation + multichannel Chat widget.
Web Push Notifications – Webpushr
webpushr-web-push-notifications
Fastest growing & lightweight plugin for Web Push Notifications. Add browser push notifications to your WordPress & WooCommerce site.
Perfecty Push Notifications
perfecty-push-notifications
Push Notifications that are self-hosted, you don't need API keys to integrate with external Push Notifications providers that will charge you lat …
Gravitec.net – Web Push Notifications
gravitec-net-web-push-notifications
Easy-to-use and smart push notifications for your website. Increase subscriptions and repeat visits with minimal effort.
iZooto – Web Push Notifications
izooto-web-push
Engage your audience and drive repeat traffic by delivering relevant and personalized push notifications - across web browsers, Android, iOS and Messe …
Pushly Developer Profile
1 plugin · 900 total installs
How We Detect Pushly
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pushly/build/meta-box.js/wp-content/plugins/pushly/build/meta-box.css/wp-content/plugins/pushly/includes/admin/views/classic/meta-box.jspushly/build/meta-box.js?ver=pushly/build/meta-box.css?ver=HTML / DOM Fingerprints
data-pushly-notification-iddata-pushly-send-notificationdata-pushly-custom-titledata-pushly-custom-bodydata-pushly-customize-audiencedata-pushly-audience-idspushlyData/wp-json/pushly/v1/post-meta