
Bootstrap Modals Security & Risk Analysis
wordpress.org/plugins/bootstrap-modalsThis plugin adds Bootstrap Modal functionality to WordPress. All you need to do is add the Modal HTML mark up code.
Is Bootstrap Modals Safe to Use in 2026?
Use With Caution
Score 63/100Bootstrap Modals has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The bootstrap-modals plugin exhibits a mixed security posture. On the positive side, the static analysis reveals no dangerous functions, no raw SQL queries, and a complete absence of file operations or external HTTP requests. The presence of capability checks suggests an attempt at securing certain functionalities. However, the lack of nonce checks on the entry points (shortcodes) is a significant concern, as it opens the door to potential Cross-Site Request Forgery (CSRF) attacks if the shortcodes can be manipulated to perform actions on behalf of logged-in users without their explicit consent. Furthermore, the 31% of output that is not properly escaped indicates a risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the website's pages.
Key Concerns
- Unpatched Medium Severity CVE
- Missing Nonce Checks on Entry Points
- Insufficient Output Escaping
Bootstrap Modals Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Bootstrap Modals <= 1.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Bootstrap Modals Code Analysis
Output Escaping
Bootstrap Modals Attack Surface
Shortcodes 2
WordPress Hooks 6
Maintenance & Trust
Bootstrap Modals Maintenance & Trust
Maintenance Signals
Community Trust
Bootstrap Modals Alternatives
Pop-up
pop-up-pop-up
Pop-up Popups
TCBD Modals
tcbd-modals
This plugin will enable Awesome Modals box in your Wordpress theme.
Boxzilla – Pop-Ups for WordPress
boxzilla
Flexible pop-ups or slide-ins, showing up at just the right time.
Poptin – Exit Pop Ups & Email Popups
poptin
Free exit intent popup builder, gamified popups with spin the wheel, contact form builder & lead generation pop ups platform for your website. 🎉
Bootstrap for Contact Form 7
bootstrap-for-contact-form-7
This plugin modifies the output of the popular Contact Form 7 plugin to be styled in compliance with themes using the Bootstrap CSS framework.
Bootstrap Modals Developer Profile
8 plugins · 9K total installs
How We Detect Bootstrap Modals
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bootstrap-modals/css/bootstrap.css/wp-content/plugins/bootstrap-modals/css/custommodal.css/wp-content/plugins/bootstrap-modals/js/bootstrap.min.js/wp-content/plugins/bootstrap-modals/js/wp-color-picker-alpha.min.js/wp-content/plugins/bootstrap-modals/js/bootstrap.min.js/wp-content/plugins/bootstrap-modals/js/wp-color-picker-alpha.min.jsbootstrap-modals/css/bootstrap.css?ver=bootstrap-modals/css/custommodal.css?ver=bootstrap-modals/js/bootstrap.min.js?ver=bootstrap-modals/js/wp-color-picker-alpha.min.js?ver=HTML / DOM Fingerprints
ng_modal_disable_bootstrap