
RollerAds – Web Push Notifications Security & Risk Analysis
wordpress.org/plugins/rolleradsRollerAds - clear and flexible web-push service for webmasters. Push notifications are successfully used to send promotional content, user information …
Is RollerAds – Web Push Notifications Safe to Use in 2026?
Generally Safe
Score 85/100RollerAds – Web Push Notifications has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The rollerads v1.1 plugin exhibits a concerning security posture despite its lack of recorded historical vulnerabilities. The static analysis reveals a critical weakness in its REST API implementation, with one route exposed without any permission callbacks. This means any unauthenticated user could potentially interact with this endpoint, leading to unintended actions or data exposure if the endpoint's functionality is sensitive. Furthermore, the complete lack of output escaping across all identified output points is a significant concern. This opens the door to Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the website that could be executed in users' browsers. While the absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests are positive indicators, the identified unprotected REST API endpoint and the pervasive unescaped output represent immediate and substantial security risks that require urgent attention.
Key Concerns
- REST API endpoint without permission callback
- Outputs not properly escaped
RollerAds – Web Push Notifications Security Vulnerabilities
RollerAds – Web Push Notifications Code Analysis
Output Escaping
RollerAds – Web Push Notifications Attack Surface
REST API Routes 1
WordPress Hooks 6
Maintenance & Trust
RollerAds – Web Push Notifications Maintenance & Trust
Maintenance Signals
Community Trust
RollerAds – Web Push Notifications Alternatives
iZooto – Web Push Notifications
izooto-web-push
Engage your audience and drive repeat traffic by delivering relevant and personalized push notifications - across web browsers, Android, iOS and Messe …
PushEngage – Web Push notification, WA Automation & Multi-Channel Chat Widget ( WA, Messenger, X, Telegram, TikTok & More)
pushengage
Send order updates, recover abandoned carts, and boost retention with push notifications, WhatsApp automation + multichannel Chat widget.
Web Push Notifications – Webpushr
webpushr-web-push-notifications
Fastest growing & lightweight plugin for Web Push Notifications. Add browser push notifications to your WordPress & WooCommerce site.
Perfecty Push Notifications
perfecty-push-notifications
Push Notifications that are self-hosted, you don't need API keys to integrate with external Push Notifications providers that will charge you lat …
Gravitec.net – Web Push Notifications
gravitec-net-web-push-notifications
Easy-to-use and smart push notifications for your website. Increase subscriptions and repeat visits with minimal effort.
RollerAds – Web Push Notifications Developer Profile
1 plugin · 100 total installs
How We Detect RollerAds – Web Push Notifications
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/rollerads/assets/css/rollerads_style.cssrollerads_style.css?ver=HTML / DOM Fingerprints
rollerads-cardform-titleregister-step-carddata-site-iddata-zone-iddata-push-textdata-push-icondata-push-titledata-subscribe-text+8 morerollerads_config/wp-json/rollerads/login