
Boot-Modal Security & Risk Analysis
wordpress.org/plugins/boot-modalThis plugin use a simple shortcode to insert a link anywhere to open any page in a Bootstrap modal window.
Is Boot-Modal Safe to Use in 2026?
Generally Safe
Score 91/100Boot-Modal has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "boot-modal" v1.10 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and implements capability checks for its identified entry points. The absence of file operations and external HTTP requests further reduces potential attack vectors. However, a significant concern arises from the low percentage (29%) of properly escaped output across 75 identified output points. This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, especially given the plugin's history of a medium-severity XSS vulnerability discovered on January 7, 2025. The static analysis reveals no critical or high severity taint flows, and the attack surface is relatively small with no immediately unprotected entry points. Despite these strengths, the prevalent lack of output escaping coupled with past XSS issues warrants careful consideration, as unsanitized output can lead to malicious code injection and user compromise.
Key Concerns
- Low output escaping rate
- Past medium severity XSS vulnerability
- No nonce checks on entry points
Boot-Modal Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Boot-Modal <= 1.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Boot-Modal Release Timeline
Boot-Modal Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Boot-Modal Attack Surface
Shortcodes 1
WordPress Hooks 13
Maintenance & Trust
Boot-Modal Maintenance & Trust
Maintenance Signals
Community Trust
Boot-Modal Alternatives
Bootstrap Shortcodes
bootstrap-shortcodes
Wordpress plugin to add shortcodes for Twitter Bootstrap 3.3
Bootstrap Modals
bootstrap-modals
This plugin adds Bootstrap Modal functionality to WordPress. All you need to do is add the Modal HTML mark up code.
Twitter's Bootstrap Shortcodes Ultimate Add-on
twitters-bootstrap-shortcodes-ultimate
Add short codes for Twitter's Bootstrap 3 CSS and components to your site add-on for Shortcodes Ultimate.
Flexia Core
flexia-core
Core plugin for Flexia theme. Controls all the plugin territory functionality for Flexia.
Lana Shortcodes
lana-shortcodes
Bootstrap framework based shortcodes
Boot-Modal Developer Profile
3 plugins · 510 total installs
How We Detect Boot-Modal
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/boot-modal/js/boot-modal.js/wp-content/plugins/boot-modal/js/boot-modal.jsboot-modal/js/boot-modal.js?ver=HTML / DOM Fingerprints
bootmodalboot-modal-open-buttonboot-modal-close-button<!-- Shortcode's params --><!-- Other params --><!-- Button or link text --><!-- Construct link or button -->data-bs-dismissdata-bs-targetdata-bs-toggledata-dismissdata-targetdata-toggle+2 morewindow.bootmodal_options[bootmodal post="post" buttonclass="" buttontext="" buttontype="" buttoncloseclass="" buttonclosetext="" size="" urlkey="" urlvalue="" animation="" dismiss="yes"]