
WebSuite Push Notifier Security & Risk Analysis
wordpress.org/plugins/websuite-push-notifierSend push notifications with custom messaging when a post is published.
Is WebSuite Push Notifier Safe to Use in 2026?
Generally Safe
Score 85/100WebSuite Push Notifier has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "websuite-push-notifier" v1.1.7 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of direct entry points like AJAX handlers, REST API routes, and shortcodes, coupled with a lack of critical or high severity taint flows, is highly positive. The plugin also demonstrates good practices in output escaping and utilizes prepared statements for a majority of its SQL queries. The limited file operations and controlled external HTTP requests further contribute to its secure design.
However, there are a few areas that warrant attention. The presence of a cron event, while not inherently insecure, represents a potential entry point if not properly secured. A single nonce check is present, but the complete absence of capability checks for any potential privileged actions is a significant concern, suggesting that certain operations might be accessible to users without proper authorization. Additionally, the bundling of an older version of Select2 (v3.5.2) could introduce vulnerabilities if the library itself has known exploits not addressed in this version. The vulnerability history being clean is a good sign, indicating a lack of past exploitable issues, but it does not negate the potential risks identified in the code analysis.
In conclusion, while the plugin avoids many common pitfalls and has a clean vulnerability record, the lack of capability checks is the most significant weakness. This, along with the outdated bundled library and the presence of an unsecured cron event, presents a moderate risk that should be addressed to achieve a more robust security profile.
Key Concerns
- Missing capability checks
- Bundled outdated library (Select2 v3.5.2)
- Cron event without explicit auth check mentioned
WebSuite Push Notifier Security Vulnerabilities
WebSuite Push Notifier Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
WebSuite Push Notifier Attack Surface
WordPress Hooks 3
Scheduled Events 1
Maintenance & Trust
WebSuite Push Notifier Maintenance & Trust
Maintenance Signals
Community Trust
WebSuite Push Notifier Alternatives
Perfecty Push Notifications
perfecty-push-notifications
Push Notifications that are self-hosted, you don't need API keys to integrate with external Push Notifications providers that will charge you lat …
Imigino Video Connect
imigino-video-connect
Imigino video player integration plugin. Embed your fully customisable Imigino video player into your WordPress content.
BiblioDAM Connect
bibliodam-connect
BiblioDAM Connect allows seamless integration of BiblioDAM media onto your WordPress website(s).
OneSignal – Web Push Notifications
onesignal-free-web-push-notifications
Increase engagement and drive more repeat traffic to your WordPress site with push notifications. Now a WordPress VIP Gold Partner.
PushEngage – Web Push notification, WA Automation & Multi-Channel Chat Widget ( WA, Messenger, X, Telegram, TikTok & More)
pushengage
Send order updates, recover abandoned carts, and boost retention with push notifications, WhatsApp automation + multichannel Chat widget.
WebSuite Push Notifier Developer Profile
3 plugins · 40 total installs
How We Detect WebSuite Push Notifier
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/websuite-push-notifier/admin/css/websuite-push-notifier-admin-style.min.css/wp-content/plugins/websuite-push-notifier/admin/assets/lib/minicolors.min.css/wp-content/plugins/websuite-push-notifier/admin/assets/lib/select2.min.css/wp-content/plugins/websuite-push-notifier/admin/assets/lib/iziToast.min.css/wp-content/plugins/websuite-push-notifier/admin/assets/lib/tooltip.min.css/wp-content/plugins/websuite-push-notifier/admin/js/websuite-push-notifier-admin.js/wp-content/plugins/websuite-push-notifier/admin/js/libs/minicolors.min.js/wp-content/plugins/websuite-push-notifier/admin/js/libs/select2.min.js+13 more/wp-content/plugins/websuite-push-notifier/admin/js/websuite-push-notifier-admin.js/wp-content/plugins/websuite-push-notifier/admin/js/libs/minicolors.min.js/wp-content/plugins/websuite-push-notifier/admin/js/libs/select2.min.js/wp-content/plugins/websuite-push-notifier/admin/js/libs/iziToast.min.js/wp-content/plugins/websuite-push-notifier/admin/js/libs/tooltip.min.js/wp-content/plugins/websuite-push-notifier/admin/js/libs/Chart.bundle.min.js+10 morewebsuite-push-notifier-admin-style.min.css?ver=minicolors.min.css?ver=select2.min.css?ver=iziToast.min.css?ver=tooltip.min.css?ver=websuite-push-notifier-admin.js?ver=minicolors.min.js?ver=select2.min.js?ver=iziToast.min.js?ver=tooltip.min.js?ver=Chart.bundle.min.js?ver=moment.min.js?ver=daterangepicker.min.js?ver=websuite-push-notifier.js?ver=websuite-push-notifier-main.js?ver=websuite-push-notifier-settings.js?ver=websuite-push-notifier-modal.js?ver=websuite-push-notifier-post-type.js?ver=websuite-push-notifier-notification-type.js?ver=websuite-push-notifier-user.js?ver=websuite-push-notifier-general-settings.js?ver=HTML / DOM Fingerprints
websuite-push-notifier-settings-sectionwebsuite-push-notifier-modal-contentwebsuite-push-notifier-post-type-settingswebsuite-push-notifier-notification-type-settingswebsuite-push-notifier-user-settingswebsuite-push-notifier-general-settings-section<!-- WebSuite Push Notifier Options --><!-- WebSuite Push Notifier Modal --><!-- WebSuite Push Notifier Post Type Settings --><!-- WebSuite Push Notifier Notification Type Settings -->+2 moredata-wspn-modaldata-wspn-post-typedata-wspn-notification-typedata-wspn-userdata-wspn-general-settingWSPN_AdminWSPN_SettingsWSPN_ModalWSPN_PostTypeWSPN_NotificationTypeWSPN_User+1 more/wp-json/wspn/v1/settings/wp-json/wspn/v1/posts/wp-json/wspn/v1/users