Claspo – Popups, Spin the Wheel & Email Capture Security & Risk Analysis

wordpress.org/plugins/claspo

Grow your email list and increase sales! Use the Claspo Popup Maker plugin to create pop-up windows, Spin the Wheel, Exit Intent, and Lead Gen forms.

1K active installs v1.0.9 PHP 7.0+ WP 1.0+ Updated Mar 2, 2026
exit-intent-popuppop-uppopuppopup-builderpopup-maker
99
A · Safe
CVEs total1
Unpatched0
Last CVEDec 17, 2025
Download
Safety Verdict

Is Claspo – Popups, Spin the Wheel & Email Capture Safe to Use in 2026?

Generally Safe

Score 99/100

Claspo – Popups, Spin the Wheel & Email Capture has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Dec 17, 2025Updated 1mo ago
Risk Assessment

The claspo v1.0.9 plugin exhibits a generally strong security posture based on the static analysis. The absence of dangerous functions, 100% use of prepared statements for SQL queries, and complete output escaping are excellent indicators of secure coding practices. Furthermore, the plugin demonstrates robust use of nonces and capability checks, which are vital for preventing common web vulnerabilities. The zero-found taint flows with unsanitized paths and zero critical or high severity issues in the taint analysis are particularly reassuring.

However, the plugin's vulnerability history warrants attention. While there are no currently unpatched vulnerabilities, a past medium severity vulnerability, specifically "Missing Authorization," was identified and resolved. This suggests that while the current version appears secure, there's a historical pattern of authorization-related flaws. The presence of two external HTTP requests without further context is a minor concern, as these could potentially be a vector for attacks if not handled with appropriate validation and sanitization on the receiving end, though no specific issues were flagged in static analysis.

In conclusion, claspo v1.0.9 is currently in a good security state due to its implementation of secure coding practices like prepared statements and output escaping. The historical "Missing Authorization" vulnerability, however, is a reminder to remain vigilant and ensure ongoing security audits, especially as the plugin evolves. The limited attack surface and absence of critical static analysis findings are positive, but the past vulnerability highlights the importance of continuous monitoring.

Key Concerns

  • Past Medium Severity Vulnerability (Missing Authorization)
  • External HTTP requests (2)
Vulnerabilities
1

Claspo – Popups, Spin the Wheel & Email Capture Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-68568medium · 5.3Missing Authorization

Claspo – Popups, Spin the Wheel & Email Capture <= 1.0.7 - Missing Authorization

Dec 17, 2025 Patched in 1.0.8 (72d)
Code Analysis
Analyzed Mar 16, 2026

Claspo – Popups, Spin the Wheel & Email Capture Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
33 escaped
Nonce Checks
5
Capability Checks
5
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

100% escaped33 total outputs
Data Flows
All sanitized

Data Flow Analysis

3 flows
claspo_check_script_id (claspo.php:46)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Claspo – Popups, Spin the Wheel & Email Capture Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionadmin_menuclaspo.php:20
actionadmin_post_claspo_save_scriptclaspo.php:21
actionadmin_post_claspo_disconnect_scriptclaspo.php:22
actionadmin_initclaspo.php:23
actionadmin_enqueue_scriptsclaspo.php:24
actionbefore_woocommerce_initclaspo.php:26
actionwp_footerclaspo.php:191
actionadmin_post_claspo_send_feedbackclaspo.php:219
actionadmin_initclaspo.php:259
actionadmin_initclaspo.php:285
Maintenance & Trust

Claspo – Popups, Spin the Wheel & Email Capture Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 2, 2026
PHP min version7.0
Downloads11K

Community Trust

Rating100/100
Number of ratings38
Active installs1K
Developer Profile

Claspo – Popups, Spin the Wheel & Email Capture Developer Profile

Claspo Popup Builders

1 plugin · 1K total installs

87
trust score
Avg Security Score
99/100
Avg Patch Time
72 days
View full developer profile
Detection Fingerprints

How We Detect Claspo – Popups, Spin the Wheel & Email Capture

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/claspo/css/main.css/wp-content/plugins/claspo/js/main2.js

HTML / DOM Fingerprints

CSS Classes
claspo-admin-styleclaspo-admin-script
FAQ

Frequently Asked Questions about Claspo – Popups, Spin the Wheel & Email Capture