
Coupon X – Discount Popups & Promo Codes Pop Ups for WooCommerce Security & Risk Analysis
wordpress.org/plugins/coupon-x-discount-pop-upBoost sales with engaging discount pop ups, coupon widgets, promo code pop up & coupon codes! Generate unique promo codes or use existing codes 🛒
Is Coupon X – Discount Popups & Promo Codes Pop Ups for WooCommerce Safe to Use in 2026?
Generally Safe
Score 98/100Coupon X – Discount Popups & Promo Codes Pop Ups for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "coupon-x-discount-pop-up" plugin v1.4.5 exhibits a mixed security posture. While it demonstrates good practices in areas like prepared SQL statements and output escaping, significant concerns remain. The presence of 15 AJAX handlers, with one lacking authentication checks, presents a direct and potentially exploitable attack vector. The use of the `unserialize` function, especially without explicit context on its data source, is a red flag for deserialization vulnerabilities.
Taint analysis shows no critical or high severity unsanitized paths, which is a positive indicator. However, the plugin's vulnerability history is concerning, with two known CVEs, including a high and a medium severity vulnerability. The common vulnerability types of "Deserialization of Untrusted Data" and "Missing Authorization" align directly with the potential risks identified in the static analysis. The fact that the last vulnerability was in early 2025 suggests a pattern of past security weaknesses that require diligent monitoring.
In conclusion, while the plugin incorporates some robust security measures, the unprotected AJAX handler and the historical recurrence of authorization and deserialization issues necessitate a cautious approach. The plugin's strengths lie in its generally good SQL and output sanitization, but these are overshadowed by the potential for privilege escalation or arbitrary code execution through the identified entry points and past vulnerabilities.
Key Concerns
- AJAX handler without auth check
- Dangerous function used (unserialize)
- Past High severity vulnerability
- Past Medium severity vulnerability
- Bundled library: Select2
- Bundled library: DataTables
Coupon X – Discount Popups & Promo Codes Pop Ups for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Coupon X: Discount Pop Up, Promo Code Pop Ups, Announcement Pop Up, WooCommerce Popups <= 1.3.5 - Missing Authorization to Authenticated (Contributor+) PHP Object Injection
Coupon X: Discount Pop Up, Promo Code Pop Ups, Announcement Pop Up, WooCommerce Popups <= 1.3.5 - Missing Authorization
Coupon X – Discount Popups & Promo Codes Pop Ups for WooCommerce Release Timeline
Coupon X – Discount Popups & Promo Codes Pop Ups for WooCommerce Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Coupon X – Discount Popups & Promo Codes Pop Ups for WooCommerce Attack Surface
AJAX Handlers 15
WordPress Hooks 22
Maintenance & Trust
Coupon X – Discount Popups & Promo Codes Pop Ups for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Coupon X – Discount Popups & Promo Codes Pop Ups for WooCommerce Alternatives
Boxzilla – Pop-Ups for WordPress
boxzilla
Flexible pop-ups or slide-ins, showing up at just the right time.
Poptin – Exit Pop Ups & Email Popups
poptin
Free exit intent popup builder, gamified popups with spin the wheel, contact form builder & lead generation pop ups platform for your website. 🎉
Pop-up
pop-up-pop-up
Pop-up Popups
Bootstrap Modals
bootstrap-modals
This plugin adds Bootstrap Modal functionality to WordPress. All you need to do is add the Modal HTML mark up code.
WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation
optin
Create stunning popups and newsletter forms with WowOptin. Boost your lead generation and sales with advanced targeting and Canva-like flexibility.
Coupon X – Discount Popups & Promo Codes Pop Ups for WooCommerce Developer Profile
9 plugins · 651K total installs
How We Detect Coupon X – Discount Popups & Promo Codes Pop Ups for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/coupon-x-discount-pop-up/assets/css/frontend.css/wp-content/plugins/coupon-x-discount-pop-up/assets/css/frontend.min.css/wp-content/plugins/coupon-x-discount-pop-up/assets/js/frontend.js/wp-content/plugins/coupon-x-discount-pop-up/assets/js/frontend.min.jsassets/js/frontend.jsassets/js/frontend.min.jscoupon-x-discount-pop-up/assets/css/frontend.css?ver=coupon-x-discount-pop-up/assets/js/frontend.js?ver=HTML / DOM Fingerprints
cx_widget_wrapcx_widget_areacx_coupon_display_boxcx_coupon_display_box_innercx_coupon_form_wrappercx_coupon_form_wrapcx_coupon_display_box_buttoncx_coupon_display_box_button_wrapper+9 more<!-- Main plugin file. --><!-- Save redirection value on plugin activation. --><!-- Coupon X settings --><!-- Coupon X widget frontend -->+4 moredata-cx_widget_iddata-cx_widget_namedata-cx_noncecx_data