DevPress Factory Elegant Popup Security & Risk Analysis

wordpress.org/plugins/devpressfactory-elegant-popup

Elegant, responsive popups with text, images, MP4/HLS video, and embed support. Compatible with Gutenberg, Elementor, and WPBakery.

0 active installs v2.0.0 PHP 7.0+ WP 4.9+ Updated Apr 5, 2026
elementormodaloverlaypopupvideo-popup
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is DevPress Factory Elegant Popup Safe to Use in 2026?

Generally Safe

Score 100/100

DevPress Factory Elegant Popup has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The 'devpressfactory-elegant-popup' plugin v2.0.0 exhibits a strong security posture based on the provided static analysis. The code demonstrates excellent adherence to secure coding practices, with all identified SQL queries utilizing prepared statements and all output properly escaped. The absence of file operations and external HTTP requests further reduces potential attack vectors. Crucially, the plugin implements nonce and capability checks on all identified entry points, indicating a commitment to protecting against common WordPress vulnerabilities.

No critical or high-severity taint flows were detected, which is a significant positive. The vulnerability history is also clean, with zero known CVEs, suggesting the developers have a proactive approach to security and have likely addressed any past issues. The limited attack surface, consisting of a single shortcode with no reported unprotected entry points, further reinforces its good security standing.

While the plugin appears very secure, the absence of any recorded vulnerability history, while positive, can sometimes indicate a lack of extensive external security auditing or a very niche user base. However, based on the static analysis alone, the plugin is well-defended. The primary strength lies in its diligent implementation of fundamental security checks like prepared statements, output escaping, and authorization checks.

Vulnerabilities
None known

DevPress Factory Elegant Popup Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

DevPress Factory Elegant Popup Release Timeline

v2.0.0Current
Code Analysis
Analyzed Apr 16, 2026

DevPress Factory Elegant Popup Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
8 prepared
Unescaped Output
0
262 escaped
Nonce Checks
4
Capability Checks
4
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared8 total queries

Output Escaping

100% escaped262 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
save_settings (includes/class-ep-admin.php:198)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

DevPress Factory Elegant Popup Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[elegant_popup] includes/class-ep-frontend.php:9
WordPress Hooks 16
actionplugins_loadedelegant-popup.php:50
actionadmin_menuincludes/class-ep-admin.php:7
actionadmin_enqueue_scriptsincludes/class-ep-admin.php:8
actionadmin_post_dpfep_save_popupincludes/class-ep-admin.php:9
actionadmin_post_dpfep_delete_popupincludes/class-ep-admin.php:10
actionadmin_post_dpfep_save_settingsincludes/class-ep-admin.php:11
actionadd_meta_boxesincludes/class-ep-admin.php:12
actionwp_enqueue_scriptsincludes/class-ep-frontend.php:7
actionwp_footerincludes/class-ep-frontend.php:8
actioninitincludes/class-ep-i18n.php:12
actionelementor/widgets/widgets_registeredincludes/integrations/class-ep-elementor.php:13
actionelementor/widgets/registerincludes/integrations/class-ep-elementor.php:15
actioninitincludes/integrations/class-ep-gutenberg.php:14
actionenqueue_block_editor_assetsincludes/integrations/class-ep-gutenberg.php:15
actionvc_before_initincludes/integrations/class-ep-wpbakery.php:13
actioninitincludes/integrations/class-ep-wpbakery.php:15
Maintenance & Trust

DevPress Factory Elegant Popup Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 5, 2026
PHP min version7.0
Downloads71

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

DevPress Factory Elegant Popup Developer Profile

devpressfactory

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect DevPress Factory Elegant Popup

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/devpressfactory-elegant-popup/admin/css/admin.css/wp-content/plugins/devpressfactory-elegant-popup/admin/js/admin.js/wp-content/plugins/devpressfactory-elegant-popup/frontend/css/elegant-popup.css/wp-content/plugins/devpressfactory-elegant-popup/frontend/js/elegant-popup.js
Script Paths
/wp-content/plugins/devpressfactory-elegant-popup/admin/js/admin.js
Version Parameters
devpressfactory-elegant-popup/admin/css/admin.css?ver=devpressfactory-elegant-popup/admin/js/admin.js?ver=devpressfactory-elegant-popup/frontend/css/elegant-popup.css?ver=devpressfactory-elegant-popup/frontend/js/elegant-popup.js?ver=

HTML / DOM Fingerprints

CSS Classes
dpfep-popup-containerdpfep-popup-closedpfep-popup-content-wrapdpfep-popup-content
HTML Comments
<!-- DevPress Factory Elegant Popup -->
Data Attributes
data-dpfep-iddata-dpfep-settings
JS Globals
dpfepAdminData
FAQ

Frequently Asked Questions about DevPress Factory Elegant Popup