
Anything Popup Security & Risk Analysis
wordpress.org/plugins/anything-popupThis is a simple plugin to display the entered content in to unblockable popup window. popup will open by clicking the text or image button.
Is Anything Popup Safe to Use in 2026?
Use With Caution
Score 63/100Anything Popup has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "anything-popup" v7.3 plugin exhibits a mixed security posture. While it demonstrates good practices in several areas, such as a very small attack surface with no identified unprotected entry points and a high percentage of SQL queries using prepared statements, there are significant concerns. The critical finding of "Flows with unsanitized paths" in the taint analysis, even without critical or high severity, suggests potential vulnerabilities that could be exploited if input is not properly handled. Furthermore, the vulnerability history reveals one unpatched medium severity CVE for Cross-site Scripting, which is a concerning pattern indicating a recurring issue that has not been fully addressed. The low percentage of properly escaped output also exacerbates the risk associated with unsanitized paths, as malicious input could be rendered directly in the browser.
Overall, the plugin has strengths in its limited attack surface and prepared SQL statements. However, the presence of unsanitized paths and a historical vulnerability for XSS, coupled with a low output escaping rate, point to a notable risk. The unpatched CVE is a direct and immediate concern that requires attention. While the static analysis didn't uncover critical or high severity issues in taint flows, the identified unsanitized paths, in conjunction with the XSS history and poor output escaping, suggest that the plugin is susceptible to cross-site scripting attacks. This plugin should be treated with caution, and the unpatched CVE must be addressed.
Key Concerns
- Unpatched medium CVE (XSS)
- Flows with unsanitized paths
- Low output escaping rate (40%)
- No capability checks on entry points
Anything Popup Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Anything Popup <= 7.3 - Reflected Cross-Site Scripting
Anything Popup Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Anything Popup Attack Surface
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
Anything Popup Maintenance & Trust
Maintenance Signals
Community Trust
Anything Popup Alternatives
WPB Popup for Contact Form 7 – Showing The Contact Form 7 Popup on Button Click – CF7 Popup
wpb-popup-for-contact-form-7
Popup for Contact Form 7 can boost your sales, leads, and conversions. It only takes a few clicks to setup a Contact Form 7 Popup on Button Click.
Popups – Submission Messages For Contact Form 7
cf7-popups
Display contact form 7 default messages in stylish popup as user submits the form.
Popup for CF7 with Sweet Alert
cf7-sweet-alert-popup
Popup for CF7 with Sweet Alert
Slick Popup: Contact Form 7 Popup Plugin
slick-popup
A lightweight plugin that converts a Contact Form 7 form into a customizable pop-up form which is slick, beautiful and responsive to different screen …
Getsitecontrol — Email Marketing Plugin | Popup Maker, Automations & Newsletters
getsitecontrol
Complete email marketing toolset with a powerful popup builder on board. Generate leads with email opt-in forms, send professional newsletters, build …
Anything Popup Developer Profile
8 plugins · 4K total installs
How We Detect Anything Popup
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/anything-popup/css/anythingPopup.css/wp-content/plugins/anything-popup/css/anythingPopup.js/wp-content/plugins/anything-popup/css/anythingPopup.jsanything-popup/css/anythingPopup.css?ver=anything-popup/css/anythingPopup.js?ver=HTML / DOM Fingerprints
AnythingPopup_BoxContainerAnythingPopup_BoxContainerHeaderAnythingPopup_BoxTitleAnythingPopup_BoxCloseAnythingPopup_BoxContainerBodyAnythingPopup_BoxContainerFooterid="AnythingPopup_BoxContainerid="AnythingPopup_BoxContainerHeaderid="AnythingPopup_BoxTitleid="AnythingPopup_BoxCloseid="AnythingPopup_BoxContainerBodyid="AnythingPopup_BoxContainerFooterAnythingPopup_OpenFormAnythingPopup_HideForm<a href='javascript:AnythingPopup_OpenForm("AnythingPopup_BoxContainer<div style="display: none;" id="AnythingPopup_BoxContainer<div id="AnythingPopup_BoxContainerHeader<div id="AnythingPopup_BoxTitle