
CocoPopup – Gutenberg Popup Builder for WordPress Security & Risk Analysis
wordpress.org/plugins/cocopopupCreate powerful popups in WordPress with CocoPopup – a flexible Gutenberg popup builder for marketing, WooCommerce & more.
Is CocoPopup – Gutenberg Popup Builder for WordPress Safe to Use in 2026?
Generally Safe
Score 100/100CocoPopup – Gutenberg Popup Builder for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "cocopopup" v2.0.1 plugin exhibits a strong security posture based on the provided static analysis. All identified entry points, including AJAX handlers and REST API routes, appear to be protected by authentication checks. The code demonstrates excellent adherence to secure coding practices with 100% of SQL queries using prepared statements and a very high percentage (97%) of outputs being properly escaped. There are no identified dangerous functions, file operations, external HTTP requests, or critical/high severity taint flows, which significantly reduces the risk of common web vulnerabilities like SQL injection, arbitrary file read/write, and remote code execution. Furthermore, the plugin has no recorded vulnerability history, suggesting a consistent commitment to security from its developers or a lack of past exploitable flaws.
While the plugin scores very highly in terms of technical security, the presence of 3 nonce checks out of 17 total entry points could indicate a slight area for improvement. Although the static analysis reports 0 unprotected entry points, a more comprehensive security review might want to ensure that all relevant AJAX actions are indeed protected by nonces. However, given the overall excellent results, this is a minor concern. The lack of any significant red flags in the static analysis and vulnerability history indicates that "cocopopup" v2.0.1 is likely a secure plugin to use.
Key Concerns
- Nonce checks present but could be more extensive
CocoPopup – Gutenberg Popup Builder for WordPress Security Vulnerabilities
CocoPopup – Gutenberg Popup Builder for WordPress Code Analysis
Output Escaping
Data Flow Analysis
CocoPopup – Gutenberg Popup Builder for WordPress Attack Surface
AJAX Handlers 5
REST API Routes 12
WordPress Hooks 26
Maintenance & Trust
CocoPopup – Gutenberg Popup Builder for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
CocoPopup – Gutenberg Popup Builder for WordPress Alternatives
Poptics – Popup Builder, Email Opt-ins, Exit-Intent & WooCommerce Popups Sales
poptics
Create high-converting popups, email opt-ins, exit-intent popups & WooCommerce popups to boost leads, subscribers and sales.
Murls Smart Popups
murls-smart-popups
The smartest free popup builder for WordPress. Create high-converting announcement popups in minutes — no coding, no bloat, no subscriptions. Ever.
Popup Builder – Create highly converting, mobile friendly marketing popups.
popup-builder
Increase Sales, Lead Generation, Conversion rates and receive good Call to Action rates with smart WordPress popup plugin.
Brave Popup Builder – Popup, Optins, Lead Generation, Survey & Interactive Content
brave-popup-builder
The best drag-and-drop Popup Builder for WordPress. Create Popups, exit-intent popups, slide-ins, and lead generation forms & Woocommerce popups i …
Modal Popup Box: A Flexible Pop Up Box Builder
modal-popup-box
Create and manage a customizable pop up box on your WordPress website. Embed anything from videos and images to forms and shortcodes.
CocoPopup – Gutenberg Popup Builder for WordPress Developer Profile
2 plugins · 80 total installs
How We Detect CocoPopup – Gutenberg Popup Builder for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cocopopup/assets/js/frontend.min.js/wp-content/plugins/cocopopup/assets/js/popup-reset-script.min.js/wp-content/plugins/cocopopup/assets/js/assets-popup.min.js/wp-content/plugins/cocopopup/assets/css/dashboard.css/wp-content/plugins/cocopopup/assets/css/custom-admin.css/wp-content/plugins/cocopopup/assets/js/frontend.min.js/wp-content/plugins/cocopopup/assets/js/popup-reset-script.min.js/wp-content/plugins/cocopopup/assets/js/assets-popup.min.jsHTML / DOM Fingerprints
cocopopup-categorydata-cocopopupfrontend_ajax_objectplugin_datawc_cart_paramspopupResetAdminScriptData