
Claspo – Popups, Spin the Wheel & Email Capture Security & Risk Analysis
wordpress.org/plugins/claspoGrow your email list and increase sales! Use the Claspo Popup Maker plugin to create pop-up windows, Spin the Wheel, Exit Intent, and Lead Gen forms.
Is Claspo – Popups, Spin the Wheel & Email Capture Safe to Use in 2026?
Generally Safe
Score 99/100Claspo – Popups, Spin the Wheel & Email Capture has a strong security track record. Known vulnerabilities have been patched promptly.
The claspo v1.0.9 plugin exhibits a generally strong security posture based on the static analysis. The absence of dangerous functions, 100% use of prepared statements for SQL queries, and complete output escaping are excellent indicators of secure coding practices. Furthermore, the plugin demonstrates robust use of nonces and capability checks, which are vital for preventing common web vulnerabilities. The zero-found taint flows with unsanitized paths and zero critical or high severity issues in the taint analysis are particularly reassuring.
However, the plugin's vulnerability history warrants attention. While there are no currently unpatched vulnerabilities, a past medium severity vulnerability, specifically "Missing Authorization," was identified and resolved. This suggests that while the current version appears secure, there's a historical pattern of authorization-related flaws. The presence of two external HTTP requests without further context is a minor concern, as these could potentially be a vector for attacks if not handled with appropriate validation and sanitization on the receiving end, though no specific issues were flagged in static analysis.
In conclusion, claspo v1.0.9 is currently in a good security state due to its implementation of secure coding practices like prepared statements and output escaping. The historical "Missing Authorization" vulnerability, however, is a reminder to remain vigilant and ensure ongoing security audits, especially as the plugin evolves. The limited attack surface and absence of critical static analysis findings are positive, but the past vulnerability highlights the importance of continuous monitoring.
Key Concerns
- Past Medium Severity Vulnerability (Missing Authorization)
- External HTTP requests (2)
Claspo – Popups, Spin the Wheel & Email Capture Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Claspo – Popups, Spin the Wheel & Email Capture <= 1.0.7 - Missing Authorization
Claspo – Popups, Spin the Wheel & Email Capture Code Analysis
Output Escaping
Data Flow Analysis
Claspo – Popups, Spin the Wheel & Email Capture Attack Surface
WordPress Hooks 10
Maintenance & Trust
Claspo – Popups, Spin the Wheel & Email Capture Maintenance & Trust
Maintenance Signals
Community Trust
Claspo – Popups, Spin the Wheel & Email Capture Alternatives
Popup Builder – Create highly converting, mobile friendly marketing popups.
popup-builder
Increase Sales, Lead Generation, Conversion rates and receive good Call to Action rates with smart WordPress popup plugin.
Modal Popup Box: A Flexible Pop Up Box Builder
modal-popup-box
Create and manage a customizable pop up box on your WordPress website. Embed anything from videos and images to forms and shortcodes.
CS Popup Maker
cs-popup-maker
A simple plugin to show popup image in homepage or any other pages which is controlled from WordPress admin panel.
Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers
popup-builder-block
Powerful Popup Builder Block for Gutenberg block editor.
WP Popups – WordPress Popup builder
wp-popups-lite
WP Popups is the best popup maker for WordPress. Easy but powerful plugin with display filters, scroll-triggered popups, and Gutenberg block editor.
Claspo – Popups, Spin the Wheel & Email Capture Developer Profile
1 plugin · 1K total installs
How We Detect Claspo – Popups, Spin the Wheel & Email Capture
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/claspo/css/main.css/wp-content/plugins/claspo/js/main2.jsHTML / DOM Fingerprints
claspo-admin-styleclaspo-admin-script