
Zaki Push Notification Security & Risk Analysis
wordpress.org/plugins/zaki-push-notificationAdd the Apple Push Notification Service (APNs) at your site.
Is Zaki Push Notification Safe to Use in 2026?
Generally Safe
Score 85/100Zaki Push Notification has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The zaki-push-notification plugin v1.1 exhibits a concerning security posture due to critical weaknesses despite some good practices. While it utilizes prepared statements for all SQL queries and makes no external HTTP requests, its handling of entry points is highly problematic. The presence of one unprotected AJAX handler, which constitutes the entire attack surface for entry points, presents a significant risk. Furthermore, the complete lack of proper output escaping across all identified outputs means that any data processed through these functions could potentially be rendered in an unsafe manner, leading to cross-site scripting (XSS) vulnerabilities. The taint analysis reveals two flows with unsanitized paths, indicating potential issues with data handling that, while not classified as critical or high, warrant attention. The absence of vulnerability history, while seemingly positive, could also indicate a lack of active security auditing or reporting, rather than genuine robustness. In conclusion, the plugin has strengths in its SQL query handling but is severely let down by its unprotected entry points and a critical deficiency in output sanitization, making it a high-risk component.
Key Concerns
- Unprotected AJAX handler
- Zero output escaping
- Flows with unsanitized paths
- Zero nonce checks
- Zero capability checks
Zaki Push Notification Security Vulnerabilities
Zaki Push Notification Release Timeline
Zaki Push Notification Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Zaki Push Notification Attack Surface
AJAX Handlers 1
WordPress Hooks 12
Maintenance & Trust
Zaki Push Notification Maintenance & Trust
Maintenance Signals
Community Trust
Zaki Push Notification Alternatives
Favicon by RealFaviconGenerator
favicon-by-realfavicongenerator
Create and install your favicon for all platforms: PC/Mac, iPhone/iPad, Android devices, Windows 8 tablets...
Smart App Banner
smart-app-banner
This is a WordPress plugin that allows you to use Smart App Banners, introduced in iOS 6, with your WordPress blog.
Push Notification Sender for WP
push-notification-sender
Easiest way to launch push notification from your WordPress website to iOs and Android devices. Ready to go, no third party any integration required.
Push Notification iOS
push-notifications-ios
This plugin allows you to send Push Notifications directly from your WordPress site to your iOS app.
Duplicate Page
duplicate-page
Duplicate Posts, Pages and Custom Posts easily using single click
Zaki Push Notification Developer Profile
5 plugins · 70 total installs
How We Detect Zaki Push Notification
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/zaki-push-notification/css/main.css/wp-content/plugins/zaki-push-notification/js/js-zaki-push-notification.js/wp-content/plugins/zaki-push-notification/js/js-zaki-push-notification.jsHTML / DOM Fingerprints
data-uploader_title="PEM Uploader"js-zaki-push-notification/wp-json/zaki-push-notification-ajax