PushPanda.io – Free Web Push Notifications Security & Risk Analysis

wordpress.org/plugins/pushpanda-free-web-push-notifications

Free web push notifications for destop and mobile browsers. Simply enable the plugin and start sending push messages to your subscribers.

40 active installs v1.1.0 PHP + WP 3.8+ Updated Sep 15, 2022
browser-push-notificationfirefox-push-notificationspushpush-notificationswebsite-push-notifications
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is PushPanda.io – Free Web Push Notifications Safe to Use in 2026?

Generally Safe

Score 85/100

PushPanda.io – Free Web Push Notifications has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "pushpanda-free-web-push-notifications" v1.1.0 plugin exhibits a seemingly strong security posture based on the provided static analysis. There are no identified dangerous functions, SQL queries are all prepared, and there are no indications of unsanitized paths in taint analysis. The absence of any recorded vulnerabilities, including critical or high severity ones, further suggests a good track record. The plugin also appears to have a minimal attack surface with no exposed AJAX handlers, REST API routes, shortcodes, or cron events that are accessible without proper authentication or permission checks.

However, there are a few areas that warrant attention and present potential risks. The low percentage of properly escaped output (33%) is a significant concern, as it indicates that a majority of data output by the plugin may be vulnerable to cross-site scripting (XSS) attacks. Additionally, the presence of external HTTP requests without clear context on their security implications or authentication could be a vector for certain types of attacks. The lack of nonce and capability checks across all identified entry points (even though there are none reported) suggests a potential oversight in implementing standard WordPress security practices that could become problematic if new entry points are introduced in future updates.

Overall, while the plugin has a clean vulnerability history and appears to follow some good security practices like using prepared statements for SQL, the significant number of unescaped outputs and the potential risks associated with external HTTP requests are notable weaknesses. The absence of common security checks like nonces and capability checks, even in a limited attack surface, is also a point of caution. Developers should prioritize addressing the output escaping issues to mitigate XSS risks. Further investigation into the external HTTP requests is also recommended.

Key Concerns

  • Low percentage of properly escaped output
  • External HTTP requests present
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

PushPanda.io – Free Web Push Notifications Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

PushPanda.io – Free Web Push Notifications Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

33% escaped6 total outputs
Attack Surface

PushPanda.io – Free Web Push Notifications Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionwp_headpushpanda.php:42
actionadmin_menupushpanda.php:43
actionadmin_initpushpanda.php:44
actionadmin_noticespushpanda.php:45
actionadmin_enqueue_scriptspushpanda.php:46
Maintenance & Trust

PushPanda.io – Free Web Push Notifications Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedSep 15, 2022
PHP min version
Downloads4K

Community Trust

Rating100/100
Number of ratings3
Active installs40
Developer Profile

PushPanda.io – Free Web Push Notifications Developer Profile

PushPanda.io

1 plugin · 40 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect PushPanda.io – Free Web Push Notifications

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/pushpanda-free-web-push-notifications/assets/css/pushpanda.css
Version Parameters
/wp-content/plugins/pushpanda-free-web-push-notifications/assets/css/pushpanda.css?ver=3

HTML / DOM Fingerprints

CSS Classes
pp-wrapperpp-headerpp-containerpp-logopp-navpp-mt-15pp-mbpp-grid+4 more
Data Attributes
data-cfasync
JS Globals
_pushpanda
FAQ

Frequently Asked Questions about PushPanda.io – Free Web Push Notifications