PushEngage: check after the CDN leak
In June 2026 Awesome Motive CDN scripts were tampered with. PushEngage was in the same incident. Plain explanation and a one-minute homepage check.

PushEngage is a notification widget. Many sites load its script from a vendor CDN, not from their own server. That is fine until the CDN is poisoned — then one changed file reaches every storefront that still embeds it.
In June 2026 Sansec described an attack on Awesome Motive’s CDN. OptinMonster, TrustPulse and PushEngage were affected. Attackers did not break into each shop. They changed JavaScript at the CDN edge.
For PushEngage the write-up called out hosts like clientcdn.pushengage.com. If your homepage still references that host, you are on the same trust path as the incident window — even if the live file looks clean today.
The payload waited for a logged-in WordPress admin, then could create rogue admins and hide a backdoor plugin. Updating the plugin in the dashboard was not enough by itself while the CDN file was wrong.
Orb44 only checks the public homepage for that CDN host. No wp-admin login. Red means the host is still in script src. Green means we did not see it on the page we fetched.
Check: orb44.com/pushengage. Related: OptinMonster, TrustPulse. Source: Sansec.
In plain terms: answer one clear question about your storefront first, then decide if you need a longer review. A one-minute check beats a week of guessing.
Keep the bar honest. A green result on a narrow check is not a forever-safe certificate. It only says what we saw on the public page we fetched right now.
If the result is red, fix the concrete thing first — the script, the open side door, the listing — then re-check. Screenshots into the admin chat work better than vague worry.
Share the checker link with whoever actually owns the site. Owners search symptoms. Admins need a binary answer they can act on today.
In plain terms: answer one clear question about your storefront first, then decide if you need a longer review. A one-minute check beats a week of guessing.
Keep the bar honest. A green result on a narrow check is not a forever-safe certificate. It only says what we saw on the public page we fetched right now.
If the result is red, fix the concrete thing first — the script, the open side door, the listing — then re-check. Screenshots into the admin chat work better than vague worry.
Share the checker link with whoever actually owns the site. Owners search symptoms. Admins need a binary answer they can act on today.