RollerAds – Web Push Notifications Security & Risk Analysis

wordpress.org/plugins/rollerads

RollerAds - clear and flexible web-push service for webmasters. Push notifications are successfully used to send promotional content, user information …

100 active installs v1.1 PHP 5.6+ WP 4.0+ Updated Apr 24, 2023
android-push-notificationsbrowser-push-notificationspush-notificationsweb-push-notificationswordpress-notifications
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is RollerAds – Web Push Notifications Safe to Use in 2026?

Generally Safe

Score 85/100

RollerAds – Web Push Notifications has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The rollerads v1.1 plugin exhibits a concerning security posture despite its lack of recorded historical vulnerabilities. The static analysis reveals a critical weakness in its REST API implementation, with one route exposed without any permission callbacks. This means any unauthenticated user could potentially interact with this endpoint, leading to unintended actions or data exposure if the endpoint's functionality is sensitive. Furthermore, the complete lack of output escaping across all identified output points is a significant concern. This opens the door to Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the website that could be executed in users' browsers. While the absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests are positive indicators, the identified unprotected REST API endpoint and the pervasive unescaped output represent immediate and substantial security risks that require urgent attention.

Key Concerns

  • REST API endpoint without permission callback
  • Outputs not properly escaped
Vulnerabilities
None known

RollerAds – Web Push Notifications Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

RollerAds – Web Push Notifications Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped7 total outputs
Attack Surface
1 unprotected

RollerAds – Web Push Notifications Attack Surface

Entry Points1
Unprotected1

REST API Routes 1

GET/wp-json/rollerads/loginincludes\api.php:11
WordPress Hooks 6
actionadmin_initincludes\admin.php:3
actionadmin_menuincludes\admin.php:4
actioninitincludes\admin.php:5
actionadmin_enqueue_scriptsincludes\admin.php:6
actionrest_api_initincludes\api.php:3
actionwp_headincludes\service-worker.php:3
Maintenance & Trust

RollerAds – Web Push Notifications Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedApr 24, 2023
PHP min version5.6
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

RollerAds – Web Push Notifications Developer Profile

rolleradsteam

1 plugin · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect RollerAds – Web Push Notifications

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/rollerads/assets/css/rollerads_style.css
Version Parameters
rollerads_style.css?ver=

HTML / DOM Fingerprints

CSS Classes
rollerads-cardform-titleregister-step-card
Data Attributes
data-site-iddata-zone-iddata-push-textdata-push-icondata-push-titledata-subscribe-text+8 more
JS Globals
rollerads_config
REST Endpoints
/wp-json/rollerads/login
FAQ

Frequently Asked Questions about RollerAds – Web Push Notifications