Dimbal Social Popup Security & Risk Analysis

wordpress.org/plugins/dimbal-social-popup

Add this plugin to show a Social Sharing Popup for your posts

10 active installs v1.2.0 PHP + WP 3.0.1+ Updated Dec 19, 2013
popuppost-sharingsocialsocial-popupsocial-sharing
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Dimbal Social Popup Safe to Use in 2026?

Generally Safe

Score 85/100

Dimbal Social Popup has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The "dimbal-social-popup" v1.2.0 plugin exhibits a generally strong security posture based on the provided static analysis. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, which significantly limits the plugin's attack surface. Furthermore, the code signals indicate the absence of dangerous functions, raw SQL queries, and file operations. The plugin also benefits from the lack of known vulnerabilities (CVEs) and a clean vulnerability history, suggesting a history of stable and secure development.

However, a significant concern arises from the output escaping analysis, where 100% of the 14 identified outputs are not properly escaped. This presents a considerable risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the website. While the plugin appears robust in other areas, this lack of output sanitization is a critical weakness that needs immediate attention. The sole capability check offers some level of access control, but the pervasive unescaped output overshadows this positive aspect.

Key Concerns

  • All outputs are unescaped
Vulnerabilities
None known

Dimbal Social Popup Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Dimbal Social Popup Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
14
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped14 total outputs
Attack Surface

Dimbal Social Popup Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
filterthe_contentindex.php:36
actionadmin_menuindex.php:126
Maintenance & Trust

Dimbal Social Popup Maintenance & Trust

Maintenance Signals

WordPress version tested3.7.41
Last updatedDec 19, 2013
PHP min version
Downloads3K

Community Trust

Rating46/100
Number of ratings3
Active installs10
Developer Profile

Dimbal Social Popup Developer Profile

benhallbenhall

5 plugins · 40 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Dimbal Social Popup

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/dimbal-social-popup/dimbal_popup.css/wp-content/plugins/dimbal-social-popup/dimbal_popup.js/wp-content/plugins/dimbal-social-popup/cancel.png
Script Paths
/wp-content/plugins/dimbal-social-popup/dimbal_popup.js
Version Parameters
dimbal_popup.css?ver=dimbal_popup.js?ver=

HTML / DOM Fingerprints

CSS Classes
dimbal_popup_wrapperdimbal_popup_containerdimbal_popup_close_icondimbal_popup_content_wrapperdimbal_popup_content_leftdimbal_popup_content_rightdimbal_popup_content_title
Data Attributes
dp_creditdp_cooldown_minutesdp_initial_delaydp_fade_in_delaydp_fade_out_delay
JS Globals
dimbal_popup_close
FAQ

Frequently Asked Questions about Dimbal Social Popup