
Auto Popup Expiry Security & Risk Analysis
wordpress.org/plugins/ape-auto-popup-expiryAuto Popup Expiry is a simple Auto Deactive Popup for Wordpress
Is Auto Popup Expiry Safe to Use in 2026?
Generally Safe
Score 85/100Auto Popup Expiry has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The ape-auto-popup-expiry v2.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, using prepared statements for all SQL queries, and making no external HTTP requests. The absence of known CVEs and the lack of recorded historical vulnerabilities suggest a generally stable and well-maintained codebase. However, significant concerns arise from the static analysis. A notable weakness is that 100% of the identified output operations are not properly escaped, posing a risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is reflected directly in the output. Furthermore, the absence of nonce checks and capability checks on any potential entry points is a critical oversight. While the attack surface is currently small with only one shortcode and no AJAX/REST API routes requiring authentication, any future expansion or even the existing shortcode could become an immediate vector for unauthorized actions or data manipulation if not properly secured. The lack of taint analysis flows analyzed is also a point of concern, as it means potential vulnerabilities in data handling might have been missed.
Key Concerns
- Unescaped output
- Missing nonce checks
- Missing capability checks
Auto Popup Expiry Security Vulnerabilities
Auto Popup Expiry Code Analysis
Output Escaping
Auto Popup Expiry Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
Auto Popup Expiry Maintenance & Trust
Maintenance Signals
Community Trust
Auto Popup Expiry Alternatives
Ultimate Popup Free
ultimate-popup-free
Ultimate PopUp Free is an AWESOME PopUp plugin for your wordpress website.
Popup Builder & Popup Maker for WordPress – OptinMonster Email Marketing and Lead Generation
optinmonster
🤩 Make popups & optin forms to get more email newsletter subscribers, leads, and sales - #1 most popular popup builder plugin! 🚀
Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder
popup-maker
Want to boost sales & marketing efforts? Use your favorite forms & builder. Unlimited popups & impressions, keep your data, no monthly subscription.
Popup Builder – Create highly converting, mobile friendly marketing popups.
popup-builder
Increase Sales, Lead Generation, Conversion rates and receive good Call to Action rates with smart WordPress popup plugin.
Lightbox & Modal Popup WordPress Plugin – FooBox
foobox-image-lightbox
A responsive image lightbox for WordPress galleries, WordPress attachments & FooGallery
Auto Popup Expiry Developer Profile
1 plugin · 20 total installs
How We Detect Auto Popup Expiry
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ape-auto-popup-expiry/images/ape.pngHTML / DOM Fingerprints
toggle<!--START-WRAPPER-APE-AUTO-POPUP-EXPIRY-->id="wrapper_auto_expiry"id="choice"[Ape]