
dream popup Security & Risk Analysis
wordpress.org/plugins/dream-popupDream Popup is a Perfect solution for any WordPress website. With a wide range of WordPress popup types, conditions, and events (From Image Popup to C …
Is dream popup Safe to Use in 2026?
Generally Safe
Score 85/100dream popup has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'dream-popup' v1.0 plugin exhibits a concerning security posture primarily due to a significant number of unprotected entry points. The static analysis reveals 6 out of 7 total entry points lack authentication checks, with all 6 being AJAX handlers. This creates a broad attack surface where unauthorized users could potentially trigger plugin functionalities. Furthermore, the presence of 3 SQL queries, none of which utilize prepared statements, alongside a taint analysis indicating a high-severity flow with unsanitized paths, points to a substantial risk of SQL injection vulnerabilities. The output escaping, while present, is only properly implemented in 42% of cases, suggesting potential for cross-site scripting (XSS) vulnerabilities. The plugin's vulnerability history is clean, with no recorded CVEs, which could indicate a lack of historical scrutiny or that past versions did not possess exploitable flaws. However, the current code analysis reveals critical weaknesses that, if exploited, could lead to severe data compromise. The absence of nonce checks and capability checks on the exposed AJAX handlers exacerbates these risks. In conclusion, while the plugin has no known past vulnerabilities, the current code analysis highlights significant and potentially critical security flaws, particularly around SQL injection and XSS, due to unprotected AJAX endpoints and insecure data handling.
Key Concerns
- AJAX handlers without authentication
- SQL queries without prepared statements
- High severity unsanitized path taint flow
- Low percentage of properly escaped output
- Lack of nonce checks on AJAX handlers
- Lack of capability checks on AJAX handlers
dream popup Security Vulnerabilities
dream popup Release Timeline
dream popup Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
dream popup Attack Surface
AJAX Handlers 6
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
dream popup Maintenance & Trust
Maintenance Signals
Community Trust
dream popup Alternatives
Popup Builder – Create highly converting, mobile friendly marketing popups.
popup-builder
Increase Sales, Lead Generation, Conversion rates and receive good Call to Action rates with smart WordPress popup plugin.
Brave Popup Builder – Popup, Optins, Lead Generation, Survey & Interactive Content
brave-popup-builder
The best drag-and-drop Popup Builder for WordPress. Create Popups, exit-intent popups, slide-ins, and lead generation forms & Woocommerce popups i …
Icegram Engage – Popups, Optins, CTAs & Lead Generation
icegram
Create high-converting popups, email optins, and CTAs in minutes. Capture leads, grow your email list, and convert visitors into customers—without cod …
Slick Popup: Contact Form 7 Popup Plugin
slick-popup
A lightweight plugin that converts a Contact Form 7 form into a customizable pop-up form which is slick, beautiful and responsive to different screen …
Keap Official Opt-in Forms
infusionsoft-official-opt-in-forms
Build your email subscriber list from visitors to your WordPress website with Keap's Official Opt-in Forms plugin.
dream popup Developer Profile
3 plugins · 10 total installs
How We Detect dream popup
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dream-popup/assets/css/style.css/wp-content/plugins/dream-popup/assets/css/fontawesome.css/wp-content/plugins/dream-popup/assets/js/script.js/wp-content/plugins/dream-popup/assets/js/script.jsdream-popup/assets/js/script.js?ver=1.0.0HTML / DOM Fingerprints
data-plugin-name="dream-popup"data-plugin-version="1.0"ajax_object