
ConvertForce Popup Builder Security & Risk Analysis
wordpress.org/plugins/convertforce-popup-builderA lightweight popup and notification bar plugin to boost your conversions without slowing down your site.
Is ConvertForce Popup Builder Safe to Use in 2026?
Generally Safe
Score 99/100ConvertForce Popup Builder has a strong security track record. Known vulnerabilities have been patched promptly.
The ConvertForce Popup Builder plugin version 0.0.9 exhibits a generally good security posture due to its adherence to several best practices. The absence of critical or high severity taint flows, along with the exclusive use of prepared statements for SQL queries and a high percentage of properly escaped output, are strong indicators of secure coding. Furthermore, the presence of nonce and capability checks on entry points, along with no reported REST API routes or shortcodes, minimizes the potential attack surface. The plugin also reports no external HTTP requests, reducing the risk of supply chain attacks or server-side request forgery vulnerabilities.
However, there are minor concerns that prevent a perfect score. The plugin does have a history of a medium severity Cross-Site Scripting (XSS) vulnerability, although it is currently patched. The static analysis also identified one file operation, which, while not inherently insecure, requires careful scrutiny to ensure it's not being used in a way that could lead to unauthorized file modifications or access. The fact that the last vulnerability was reported in the future (2026) is likely a data anomaly and should be disregarded in the current assessment.
Overall, ConvertForce Popup Builder version 0.0.9 appears to be a relatively secure plugin, with most potential vulnerabilities addressed through good coding practices and a patched vulnerability history. The presence of a single medium XSS vulnerability in the past, coupled with the file operation, suggests a need for continued vigilance and thorough review of any future updates.
Key Concerns
- Past Medium severity XSS vulnerability
- File operations present
ConvertForce Popup Builder Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
ConvertForce Popup Builder <= 0.0.7 - Stored Cross-Site Scripting via entrance_animation
ConvertForce Popup Builder Code Analysis
Output Escaping
ConvertForce Popup Builder Attack Surface
AJAX Handlers 1
WordPress Hooks 9
Maintenance & Trust
ConvertForce Popup Builder Maintenance & Trust
Maintenance Signals
Community Trust
ConvertForce Popup Builder Alternatives
Lightbox & Modal Popup WordPress Plugin – FooBox
foobox-image-lightbox
A responsive image lightbox for WordPress galleries, WordPress attachments & FooGallery
My Sticky Bar – Floating Notification Bar & Sticky Header (formerly myStickymenu)
mystickymenu
Create a welcome notification bar for your website. Also, My Sticky Bar plugin can make your menu or header sticky to the top when scrolled 📌
WP Lightbox 2
wp-lightbox-2
WP Lightbox 2 adds stunning lightbox effects to images and galleries on your WordPress site.
Video PopUp
video-popup
The ultimate Video Popup plugin for WordPress. Create unlimited and responsive popups for YouTube, Vimeo, MP4 & WebM videos on click or On-Page Load.
ARI Fancy Lightbox – Popup for WordPress
ari-fancy-lightbox
Lightbox for WordPress with social and viral features. Show photos, gallery, PDF, videos, WooCommerce images, inline content, Google Maps links.
ConvertForce Popup Builder Developer Profile
7 plugins · 16K total installs
How We Detect ConvertForce Popup Builder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/convertforce-popup-builder/build/admin-page.js/wp-content/plugins/convertforce-popup-builder/build/admin-page.asset.php/wp-content/plugins/convertforce-popup-builder/assets/css/admin-page-style.cssconvertforce-popup-builder/build/admin-page.js?ver=convertforce-popup-builder/assets/css/admin-page-style.css?ver=HTML / DOM Fingerprints
convertforce-admin-wrap-outerswitchsliderrounddata-post-idCONVERTFORCE_ADMIN/wp-json/convertforce/v1/popup