
ConvBoost Exit Rescue Security & Risk Analysis
wordpress.org/plugins/convboost-exit-rescueReduce mobile bounces with exit intent rescue: redirect back-button exits to a chosen page (offers, lead magnets, best sellers).
Is ConvBoost Exit Rescue Safe to Use in 2026?
Generally Safe
Score 100/100ConvBoost Exit Rescue has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "convboost-exit-rescue" v0.3.0 presents a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and includes nonce and capability checks for most of its entry points. The absence of known CVEs and common vulnerability types in its history is also a strong indicator of past security diligence. Furthermore, the plugin avoids file operations and external HTTP requests, which are common vectors for exploitation.
However, a significant concern arises from the static analysis, which reveals one AJAX handler that lacks authentication checks. This unprotected entry point represents a direct attack vector, potentially allowing unauthorized users to trigger functionality or interact with the plugin in unintended ways. While taint analysis shows no immediate critical or high severity flows, the presence of an unprotected AJAX handler means that any data passed to it could be considered untrusted. The output escaping is also only at 42%, which means a substantial portion of outputs are not properly sanitized, increasing the risk of Cross-Site Scripting (XSS) vulnerabilities if data from these outputs is not handled carefully by the application consuming them.
In conclusion, the plugin has a solid foundation with its handling of SQL and its vulnerability history. Nevertheless, the single unprotected AJAX handler and the low percentage of properly escaped outputs are notable weaknesses that require attention. Addressing the unprotected AJAX handler and improving output sanitization would significantly enhance the plugin's overall security.
Key Concerns
- Unprotected AJAX handler
- Low percentage of properly escaped output
ConvBoost Exit Rescue Security Vulnerabilities
ConvBoost Exit Rescue Code Analysis
Output Escaping
ConvBoost Exit Rescue Attack Surface
AJAX Handlers 3
WordPress Hooks 6
Maintenance & Trust
ConvBoost Exit Rescue Maintenance & Trust
Maintenance Signals
Community Trust
ConvBoost Exit Rescue Alternatives
Poptics – Popup Builder, Email Opt-ins, Exit-Intent & WooCommerce Popups Sales
poptics
Create high-converting popups, email opt-ins, exit-intent popups & WooCommerce popups to boost leads, subscribers and sales.
Cart Lift – Abandoned Cart Recovery for WooCommerce and EDD
cart-lift
Track abandoned carts and send automated, customizable abandoned cart recovery emails. Get more leads, reduce cart abandonment, and increase revenue.
Claspo – Popups, Spin the Wheel & Email Capture
claspo
Grow your email list and increase sales! Use the Claspo Popup Maker plugin to create pop-up windows, Spin the Wheel, Exit Intent, and Lead Gen forms.
Personizely — A/B Testing, Personalization, Popups & CRO
personizely
Personizely is a Conversion Optimization Toolkit that helps you boost engagement and sales through A/B testing, website personalization, and popups.
Easy Popup – Welcome Popup, Email Popup, Exit Popup
easy-popup
Easy Popup includes Welcome Popup, Video Popup, Email Capture Popup, Social Coupon Popup & Custom HTML Popup. Responsive and Exit Intent Popups.
ConvBoost Exit Rescue Developer Profile
2 plugins · 0 total installs
How We Detect ConvBoost Exit Rescue
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/convboost-exit-rescue/assets/admin.css/wp-content/plugins/convboost-exit-rescue/assets/admin.js/wp-content/plugins/convboost-exit-rescue/assets/admin.jsconvboost-exit-rescue/assets/admin.css?ver=convboost-exit-rescue/assets/admin.js?ver=HTML / DOM Fingerprints
convbst-er-tiparia-labeltitleCONVBST_ER_ADMIN