ConvertForce Popup Builder Security & Risk Analysis

wordpress.org/plugins/convertforce-popup-builder

A lightweight popup and notification bar plugin to boost your conversions without slowing down your site.

50 active installs v0.0.9 PHP 7.0+ WP 6.1+ Updated Mar 9, 2026
floating-barlightboxnotification-barpopupslide-in
99
A · Safe
CVEs total1
Unpatched0
Last CVEJan 9, 2026
Safety Verdict

Is ConvertForce Popup Builder Safe to Use in 2026?

Generally Safe

Score 99/100

ConvertForce Popup Builder has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jan 9, 2026Updated 25d ago
Risk Assessment

The ConvertForce Popup Builder plugin version 0.0.9 exhibits a generally good security posture due to its adherence to several best practices. The absence of critical or high severity taint flows, along with the exclusive use of prepared statements for SQL queries and a high percentage of properly escaped output, are strong indicators of secure coding. Furthermore, the presence of nonce and capability checks on entry points, along with no reported REST API routes or shortcodes, minimizes the potential attack surface. The plugin also reports no external HTTP requests, reducing the risk of supply chain attacks or server-side request forgery vulnerabilities.

However, there are minor concerns that prevent a perfect score. The plugin does have a history of a medium severity Cross-Site Scripting (XSS) vulnerability, although it is currently patched. The static analysis also identified one file operation, which, while not inherently insecure, requires careful scrutiny to ensure it's not being used in a way that could lead to unauthorized file modifications or access. The fact that the last vulnerability was reported in the future (2026) is likely a data anomaly and should be disregarded in the current assessment.

Overall, ConvertForce Popup Builder version 0.0.9 appears to be a relatively secure plugin, with most potential vulnerabilities addressed through good coding practices and a patched vulnerability history. The presence of a single medium XSS vulnerability in the past, coupled with the file operation, suggests a need for continued vigilance and thorough review of any future updates.

Key Concerns

  • Past Medium severity XSS vulnerability
  • File operations present
Vulnerabilities
1

ConvertForce Popup Builder Security Vulnerabilities

CVEs by Year

1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-14506medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

ConvertForce Popup Builder <= 0.0.7 - Stored Cross-Site Scripting via entrance_animation

Jan 9, 2026 Patched in 0.0.8 (1d)
Code Analysis
Analyzed Mar 16, 2026

ConvertForce Popup Builder Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
24 escaped
Nonce Checks
1
Capability Checks
2
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

92% escaped26 total outputs
Attack Surface

ConvertForce Popup Builder Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_convertforce_toggle_post_statusinc\Core\Post.php:49
WordPress Hooks 9
actioninitconvertforce-popup-builder.php:31
actionadmin_initconvertforce-popup-builder.php:32
actionadmin_menuconvertforce-popup-builder.php:33
actionwp_footerconvertforce-popup-builder.php:34
actionsave_postconvertforce-popup-builder.php:35
actionwpconvertforce-popup-builder.php:36
actionadmin_enqueue_scriptsinc\Core\Post.php:46
actionpre_get_postsinc\Core\Post.php:53
filterscript_loader_taginc\Core\Post.php:178
Maintenance & Trust

ConvertForce Popup Builder Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 9, 2026
PHP min version7.0
Downloads746

Community Trust

Rating100/100
Number of ratings1
Active installs50
Developer Profile

ConvertForce Popup Builder Developer Profile

Imtiaz Rayhan

7 plugins · 16K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
313 days
View full developer profile
Detection Fingerprints

How We Detect ConvertForce Popup Builder

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/convertforce-popup-builder/build/admin-page.js/wp-content/plugins/convertforce-popup-builder/build/admin-page.asset.php/wp-content/plugins/convertforce-popup-builder/assets/css/admin-page-style.css
Version Parameters
convertforce-popup-builder/build/admin-page.js?ver=convertforce-popup-builder/assets/css/admin-page-style.css?ver=

HTML / DOM Fingerprints

CSS Classes
convertforce-admin-wrap-outerswitchsliderround
Data Attributes
data-post-id
JS Globals
CONVERTFORCE_ADMIN
REST Endpoints
/wp-json/convertforce/v1/popup
FAQ

Frequently Asked Questions about ConvertForce Popup Builder