Epic Popup Creator Security & Risk Analysis

wordpress.org/plugins/epic-popup-creator

An easy to use and light plugin for creating popup with user friendly interface.

0 active installs v1.0.0 PHP 5.6+ WP 5.3+ Updated May 29, 2020
advertisingmarketingoptinpopuppopups
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Epic Popup Creator Safe to Use in 2026?

Generally Safe

Score 85/100

Epic Popup Creator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The static analysis of "epic-popup-creator" v1.0.0 reveals a generally good security posture, particularly in its handling of data integrity. The absence of any detected dangerous functions, external HTTP requests, file operations, and the exclusive use of prepared statements for SQL queries are strong indicators of secure coding practices. The taint analysis showing zero flows with unsanitized paths further supports this. However, the security posture is significantly weakened by the complete lack of nonces and capability checks. While the attack surface is currently zero, this is likely due to the plugin's current limited functionality or perhaps an oversight in the static analysis setup, as any interaction point should ideally be secured. The limited output escaping is also a minor concern, potentially leaving room for cross-site scripting (XSS) vulnerabilities if new functionality is added without proper sanitization.

Key Concerns

  • No nonce checks implemented
  • No capability checks implemented
  • Significant portion of output not escaped
Vulnerabilities
None known

Epic Popup Creator Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Epic Popup Creator Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
25 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

78% escaped32 total outputs
Attack Surface

Epic Popup Creator Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionplugins_loadedepic-popup-creator.php:23
actioninitepic-popup-creator.php:57
actioninitepic-popup-creator.php:62
actioninitepic-popup-creator.php:69
actionwp_enqueue_scriptsepic-popup-creator.php:78
actioncarbon_fields_register_fieldsepic-popup-creator.php:113
actionwp_footerepic-popup-creator.php:197
filtermanage_posts_columnsepic-popup-creator.php:212
filtermanage_posts_custom_columnepic-popup-creator.php:247
actionrestrict_manage_postsepic-popup-creator.php:309
actionpre_get_postsepic-popup-creator.php:363
Maintenance & Trust

Epic Popup Creator Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedMay 29, 2020
PHP min version5.6
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Epic Popup Creator Developer Profile

Arnab Mondal

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Epic Popup Creator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/epic-popup-creator/assets/css/modal.css/wp-content/plugins/epic-popup-creator/assets/js/plain-modal.min.js/wp-content/plugins/epic-popup-creator/assets/js/popupcreator-main.js
Version Parameters
epic-popup-creator/assets/css/modal.css?ver=epic-popup-creator/assets/js/plain-modal.min.js?ver=epic-popup-creator/assets/js/popupcreator-main.js?ver=

HTML / DOM Fingerprints

CSS Classes
modal-contentclose-button-containerclose-buttonppc-popup-imageppc-main-text-containerpop-textpop-button
Data Attributes
data-modal-idauto-hidedata-sizedata-exitdata-delaymodal-id-
JS Globals
plainmodal-js
FAQ

Frequently Asked Questions about Epic Popup Creator