
Cool fade popup Security & Risk Analysis
wordpress.org/plugins/cool-fade-popupSometimes its useful to add a popup to your site to show your announcement. Using this plugin you can create unblockable popups for your site.
Is Cool fade popup Safe to Use in 2026?
Use With Caution
Score 63/100Cool fade popup has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "cool-fade-popup" plugin v10.1 exhibits a mixed security posture. On the positive side, the static analysis reveals a limited attack surface with no identified AJAX handlers or REST API routes exposed without proper authentication checks. The plugin also demonstrates good practices with a high percentage of SQL queries using prepared statements and a reasonable number of nonce and capability checks. File operations and external HTTP requests are absent, further reducing potential vulnerabilities.
However, several areas raise concerns. A significant weakness is the low percentage of properly escaped outputs (42%), indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. This is exacerbated by the fact that there are no identified critical or high severity taint flows, suggesting potential vulnerabilities might be overlooked or not detected by the specific analysis performed, and that the low output escaping percentage is the primary concern for client-side code injection.
The vulnerability history highlights a recurring issue with SQL Injection, with one medium severity CVE currently unpatched from July 2025. The fact that the last vulnerability was a medium severity SQL injection and that there is an unpatched CVE points to a potential pattern of insecure coding practices related to database interactions, despite the high usage of prepared statements. This suggests that even with prepared statements, the implementation might be flawed, or other SQL-related vulnerabilities exist.
Key Concerns
- Unpatched CVE (medium severity)
- Low output escaping percentage (42%)
- Vulnerability history indicates SQL injection issues
Cool fade popup Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Cool fade popup <= 10.1 - Authenticated (Contributor+) SQL Injection
Cool fade popup Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Cool fade popup Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
Cool fade popup Maintenance & Trust
Maintenance Signals
Community Trust
Cool fade popup Alternatives
Popup Builder & Popup Maker for WordPress – OptinMonster Email Marketing and Lead Generation
optinmonster
🤩 Make popups & optin forms to get more email newsletter subscribers, leads, and sales - #1 most popular popup builder plugin! 🚀
Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder
popup-maker
Want to boost sales & marketing efforts? Use your favorite forms & builder. Unlimited popups & impressions, keep your data, no monthly subscription.
Advanced Popups
advanced-popups
Display high-converting newsletter popups, a cookie notice, or a notification with the light-weight yet feature-rich plugin.
Popup Box – Create Countdown, Coupon, Video, Contact Form Popups
ays-popup-box
Build flexible popups and modal windows with multiple popup types, triggers, and display controls.
WP Popups – WordPress Popup builder
wp-popups-lite
WP Popups is the best popup maker for WordPress. Easy but powerful plugin with display filters, scroll-triggered popups, and Gutenberg block editor.
Cool fade popup Developer Profile
52 plugins · 19K total installs
How We Detect Cool fade popup
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cool-fade-popup/PopUpFad.css/wp-content/plugins/cool-fade-popup/PopUpFad.js/wp-content/plugins/cool-fade-popup/PopUpFad.jscool-fade-popup/PopUpFad.csscool-fade-popup/PopUpFad.jsHTML / DOM Fingerprints
PopUpFadClosePopUpFad_SessionPopUpFadOpenPopUpFadCloseX[cool-fade-popup]