Easy Free Popup Security & Risk Analysis

wordpress.org/plugins/easy-free-popup

Free customizable popup plugin with basic functionality. Supports Facebook, Instagram, Twitter etc. SEO friendly.

10 active installs v0.1 PHP + WP 4.6+ Updated Jan 15, 2017
free-popuppopupseo-friendly-popupseo-popupsocial-media-popup
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Easy Free Popup Safe to Use in 2026?

Generally Safe

Score 85/100

Easy Free Popup has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The 'easy-free-popup' plugin v0.1 exhibits an exceptionally low attack surface in its static analysis, with no identified AJAX handlers, REST API routes, shortcodes, or cron events. The code also demonstrates good practices by not utilizing dangerous functions, performing file operations, or making external HTTP requests. The absence of any recorded vulnerabilities or CVEs further contributes to a seemingly secure profile. However, the analysis does highlight a concern regarding output escaping, with only 72% of outputs being properly escaped. This suggests a potential for cross-site scripting (XSS) vulnerabilities if the unescaped data originates from user input or untrusted sources. Furthermore, the complete lack of nonce and capability checks across all potential entry points, though currently minimal, presents a significant risk if the attack surface were to expand in future versions. The plugin's vulnerability history is clean, but this is for a very early version, which doesn't guarantee future security.

Key Concerns

  • Incomplete output escaping (28% unescaped)
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

Easy Free Popup Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Easy Free Popup Release Timeline

v0.1Current
Code Analysis
Analyzed Apr 16, 2026

Easy Free Popup Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
13
33 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

72% escaped46 total outputs
Attack Surface

Easy Free Popup Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionwp_enqueue_scriptseasy-free-popup.php:18
actionwp_enqueue_scriptseasy-free-popup.php:36
actionwp_enqueue_scriptseasy-free-popup.php:44
actionwp_footereasy-free-popup.php:119
actionadmin_menusettings.php:17
actionadmin_initsettings.php:183
Maintenance & Trust

Easy Free Popup Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.33
Last updatedJan 15, 2017
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Easy Free Popup Developer Profile

jcuryllo

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Easy Free Popup

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/easy-free-popup/css/styles.css/wp-content/plugins/easy-free-popup/js/scripts.js
Script Paths
/wp-content/plugins/easy-free-popup/js/scripts.js
Version Parameters
easy-free-popup/css/styles.css?ver=easy-free-popup/js/scripts.js?ver=

HTML / DOM Fingerprints

CSS Classes
efp-modalefp-modal-contentefp-modal-headerefp-modal-bodyefp-justify-textefp-padding-textefp-center-textefp-social-box+1 more
Data Attributes
id="efp_modal"id="efp_close"
JS Globals
efp_options
FAQ

Frequently Asked Questions about Easy Free Popup