
Choyal Subscription Popup – MailChimp Support Security & Risk Analysis
wordpress.org/plugins/choyal-subscription-popupChoyal Subscription Popup fully customizable popup. Full control over popup heading, text, popup background overlay and background image.
Is Choyal Subscription Popup – MailChimp Support Safe to Use in 2026?
Generally Safe
Score 85/100Choyal Subscription Popup – MailChimp Support has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "choyal-subscription-popup" v2.0 plugin demonstrates some positive security practices, including a complete absence of known vulnerabilities (CVEs) and no reported past security issues. Furthermore, all identified entry points, including AJAX handlers, shortcodes, REST API routes, and cron events, appear to have proper authorization and capability checks, along with robust nonce checks for AJAX requests. The taint analysis also indicates no critical or high severity flows with unsanitized paths. This suggests a generally good security posture for this version.
However, there are a few areas that warrant attention. The presence of the `unserialize` function is a significant code signal that could be a potential risk if user-supplied data is directly passed to it without proper sanitization. Additionally, the fact that 100% of SQL queries are not using prepared statements is a concern, as this can lead to SQL injection vulnerabilities. While the taint analysis found no current issues, the potential for exploitation exists with these raw SQL queries. The proper output escaping is reasonably high at 77%, but the remaining 23% could still pose a risk for cross-site scripting (XSS) vulnerabilities if user-controllable data is involved.
In conclusion, while "choyal-subscription-popup" v2.0 shows strengths in its lack of known vulnerabilities and comprehensive checks on entry points, the use of `unserialize` and the complete absence of prepared statements for SQL queries represent notable weaknesses. Addressing these specific code signals should be a priority to further strengthen the plugin's security.
Key Concerns
- Dangerous function 'unserialize' found
- SQL queries not using prepared statements
- Output not properly escaped (23%)
Choyal Subscription Popup – MailChimp Support Security Vulnerabilities
Choyal Subscription Popup – MailChimp Support Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Choyal Subscription Popup – MailChimp Support Attack Surface
AJAX Handlers 7
WordPress Hooks 5
Maintenance & Trust
Choyal Subscription Popup – MailChimp Support Maintenance & Trust
Maintenance Signals
Community Trust
Choyal Subscription Popup – MailChimp Support Alternatives
Yeloni Exit Popup | (Free) GDPR Compliance
yeloni-free-exit-popup
Powerful lead generation plugin that converts abandoning visitors into subscribers using exit intent, page level targeting & custom designs.
Yeloni Customizable Popup for Mailchimp
yeloni-customizable-popup-for-mailchimp
This plugin lets you create Email Subscription Popups using Mailchimp. You can customize the design and configure behavior of the popup.
CB MailChimp Popup Subscriber
cb-popup-subscriber
You can show popup email subscription message for your website with Mailchimp
Hustle – Email Marketing, Lead Generation, Optins, Popups
wordpress-popup
Setup email optin forms, popups, newsletter forms & subscription forms to generate email leads with the best marketing popup builder
MailOptin – Popup, Optin Forms & Email Newsletters for Mailchimp, HubSpot, AWeber Etc.
mailoptin
Create popup, optin forms using easy form builder & popup maker. Send automated email to subscribers — Mailchimp, ActiveCampaign, Campaign Monitor etc
Choyal Subscription Popup – MailChimp Support Developer Profile
4 plugins · 30 total installs
How We Detect Choyal Subscription Popup – MailChimp Support
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/choyal-subscription-popup/assets/css/style.css/wp-content/plugins/choyal-subscription-popup/assets/js/jquery.validate.min.js/wp-content/plugins/choyal-subscription-popup/assets/js/script.js/wp-content/plugins/choyal-subscription-popup/assets/js/jquery.validate.min.js/wp-content/plugins/choyal-subscription-popup/assets/js/script.jschoyal-subscription-popup/assets/css/style.css?ver=choyal-subscription-popup/assets/js/jquery.validate.min.js?ver=choyal-subscription-popup/assets/js/script.js?ver=HTML / DOM Fingerprints
csp_subscribe_btncsp_btn_img_iconcsp_overlaycsp_modelcsp_contentcsp_closecsp_api_msgcsp-popup-heading+9 moreid="email-subscription-form"name="csp_fname"name="csp_lname"name="csp_email"name="csp_submit"csp_ajax/wp-json/csp_submit