
Boxzilla – WordPress Popup Builder Security & Risk Analysis
wordpress.org/plugins/boxzillaCreate WordPress popup and slide-in boxes for forms, offers, notices, and calls to action
Is Boxzilla – WordPress Popup Builder Safe to Use in 2026?
Generally Safe
Score 100/100Boxzilla – WordPress Popup Builder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The Boxzilla plugin v3.4.7 presents a mixed security posture. On the positive side, it demonstrates good practices in its handling of SQL queries, utilizing prepared statements for all 11 queries. Furthermore, the plugin has no recorded vulnerabilities (CVEs), which is a strong indicator of past security diligence. However, the static analysis reveals several areas of concern. The presence of an unprotected AJAX handler represents a significant security risk, as it could be exploited without proper user authentication. While the plugin has a reasonable percentage of properly escaped outputs, a notable 28% remain unescaped, which could lead to Cross-Site Scripting (XSS) vulnerabilities if malicious data is processed. The taint analysis indicates two flows with unsanitized paths, though thankfully these did not reach critical or high severity levels in this analysis. The complete absence of nonce checks on any entry points is also a deficiency. The plugin's strengths lie in its SQL security and lack of past vulnerabilities, but the unprotected AJAX handler and output escaping issues are areas that require immediate attention to strengthen its overall security.
Key Concerns
- Unprotected AJAX handler
- Significant unescaped output
- Taint flows with unsanitized paths
- No nonce checks on entry points
Boxzilla – WordPress Popup Builder Security Vulnerabilities
Boxzilla – WordPress Popup Builder Release Timeline
Boxzilla – WordPress Popup Builder Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Boxzilla – WordPress Popup Builder Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 45
Scheduled Events 1
Maintenance & Trust
Boxzilla – WordPress Popup Builder Maintenance & Trust
Maintenance Signals
Community Trust
Boxzilla – WordPress Popup Builder Alternatives
BytePopup
bytepopup
A lightweight, easy-to-use popup builder for WordPress to capture leads and increase conversions.
Popup Box – Create Countdown, Coupon, Video, Contact Form Popups
ays-popup-box
Build flexible popups and modal windows with multiple popup types, triggers, and display controls.
WP Popups – WordPress Popup builder
wp-popups-lite
WP Popups is the best popup maker for WordPress. Easy but powerful plugin with display filters, scroll-triggered popups, and Gutenberg block editor.
Pop-up
pop-up-pop-up
Pop-up Popups
Smart Popup by Supsystic
popup-by-supsystic
Create targeted popups for lead capture, event notifications, announcements, and promotions — shown at the right time without disrupting your visitors …
Boxzilla – WordPress Popup Builder Developer Profile
9 plugins · 1.1M total installs
How We Detect Boxzilla – WordPress Popup Builder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/boxzilla/admin/css/boxzilla-admin.css/wp-content/plugins/boxzilla/admin/js/boxzilla-admin.js/wp-content/plugins/boxzilla/public/css/boxzilla.css/wp-content/plugins/boxzilla/public/js/boxzilla.js/wp-content/plugins/boxzilla/admin/js/boxzilla-admin.js/wp-content/plugins/boxzilla/public/js/boxzilla.jsboxzilla/admin/css/boxzilla-admin.css?ver=boxzilla/admin/js/boxzilla-admin.js?ver=boxzilla/public/css/boxzilla.css?ver=boxzilla/public/js/boxzilla.js?ver=HTML / DOM Fingerprints
boxzilla-boxboxzilla-closeboxzilla-overlayboxzilla-contentBoxzilla PluginCopyright (C) 2013 Danny van KootenThis program is free software: you can redistribute it and/or modifyThis program is distributed in the hope that it will be useful+4 moredata-boxzilla-iddata-boxzilla-delaydata-boxzilla-expiresdata-boxzilla-cookie-pathdata-boxzilla-cookie-domaindata-boxzilla-cookie-same-site+7 moreBoxzilla