
Pushover Notifications for WordPress Security & Risk Analysis
wordpress.org/plugins/pushover-notificationsPushover Notifications allows your WordPress site to send push notifications straight to your iOS/Android device.
Is Pushover Notifications for WordPress Safe to Use in 2026?
Generally Safe
Score 85/100Pushover Notifications for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The pushover-notifications plugin v1.9.4 presents a mixed security posture. On the positive side, it has no recorded vulnerabilities (CVEs) and its attack surface appears to be well-controlled, with no unprotected AJAX handlers, REST API routes, or shortcodes. The presence of nonce and capability checks, along with the absence of dangerous functions and file operations, are good security practices. However, significant concerns arise from the static analysis. The plugin uses raw SQL queries without prepared statements, which is a common vector for SQL injection vulnerabilities. Furthermore, a concerning percentage of its output is not properly escaped, leaving it susceptible to cross-site scripting (XSS) attacks. The taint analysis revealing flows with unsanitized paths, though not critical or high severity, indicates potential for data manipulation or unintended execution if these paths were to intersect with sensitive operations. The lack of historical vulnerabilities is positive, but the identified code-level weaknesses suggest that the plugin's security is more a result of its limited functionality rather than robust secure coding practices. Continued vigilance and addressing the identified code quality issues are recommended.
Key Concerns
- SQL queries not using prepared statements
- Low percentage of properly escaped output
- Flows with unsanitized paths detected
Pushover Notifications for WordPress Security Vulnerabilities
Pushover Notifications for WordPress Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Pushover Notifications for WordPress Attack Surface
WordPress Hooks 23
Scheduled Events 1
Maintenance & Trust
Pushover Notifications for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Pushover Notifications for WordPress Alternatives
Pushover Notifications for Jetpack
pushover-notifications-for-jetpack
Integrates Jetpack with the Pushover Notifications for WordPress plugin.
OneSignal – Web Push Notifications
onesignal-free-web-push-notifications
Increase engagement and drive more repeat traffic to your WordPress site with push notifications. Now a WordPress VIP Gold Partner.
PushEngage – Web Push notification, WA Automation & Multi-Channel Chat Widget ( WA, Messenger, X, Telegram, TikTok & More)
pushengage
Send order updates, recover abandoned carts, and boost retention with push notifications, WhatsApp automation + multichannel Chat widget.
Web Push Notifications – Webpushr
webpushr-web-push-notifications
Fastest growing & lightweight plugin for Web Push Notifications. Add browser push notifications to your WordPress & WooCommerce site.
Push Notifications by LaraPush
push-notifications-by-larapush
LaraPush's "Push Notifications" is a premium add-on exclusively available for the larapush pro panel. With this add-on, users can easil …
Pushover Notifications for WordPress Developer Profile
9 plugins · 860 total installs
How We Detect Pushover Notifications for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pushover-notifications/includes/scripts/ckpn_custom.js/wp-content/plugins/pushover-notifications/includes/scripts/ckpn_custom.jspushover-notifications/includes/scripts/ckpn_custom.js?ver=HTML / DOM Fingerprints
CKPN_VERSIONCKPN_URLCKPN_CORE_TEXT_DOMAIN