Exit Intent Security & Risk Analysis

wordpress.org/plugins/exit-intent

Exit Intent makes it insanely easy to convert abandoning visitors into subscribers, and sales! Reduce bounce rates and boost conversions.

10 active installs v1.1.32 PHP + WP 3.6+ Updated Apr 12, 2019
bounceexitexit-popupexit-intent
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Exit Intent Safe to Use in 2026?

Generally Safe

Score 85/100

Exit Intent has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The "exit-intent" plugin v1.1.32 exhibits a generally positive security posture based on the static analysis and vulnerability history provided. There are no identified vulnerabilities in its history, and the static analysis shows a lack of dangerous functions, SQL injection risks (all queries use prepared statements), and external HTTP requests. The plugin also avoids bundled libraries, which can sometimes introduce outdated and vulnerable components. The presence of capability checks is a good sign for access control. However, a significant concern is the complete absence of output escaping. This means that any data rendered by the plugin, if it were to originate from an untrusted source (though no such sources are apparent in the analysis), could potentially be rendered in an unsafe manner, leading to cross-site scripting (XSS) vulnerabilities. The lack of any identified taint flows is reassuring, but the unescaped output remains a notable weakness. The plugin's small attack surface is a strength, but the lack of security checks on its zero entry points is somewhat concerning as it implies either no user interaction points or a reliance on WordPress core for all security, which isn't always sufficient. The absence of historical vulnerabilities is a strong indicator of good development practices, but it does not negate the immediate risks identified in the static analysis.

Key Concerns

  • Output escaping is not implemented
Vulnerabilities
None known

Exit Intent Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Exit Intent Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped6 total outputs
Attack Surface

Exit Intent Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actioninitexit-intent.php:12
actionadmin_noticesexit-intent.php:13
filterplugin_action_linksexit-intent.php:14
actionwp_footerexit-intent.php:15
actionadmin_footerexit-intent.php:16
actionadmin_menuexit-intent.php:21
actionadmin_menuexit-intent.php:22
Maintenance & Trust

Exit Intent Maintenance & Trust

Maintenance Signals

WordPress version tested5.0.0
Last updatedApr 12, 2019
PHP min version
Downloads21K

Community Trust

Rating60/100
Number of ratings4
Active installs10
Developer Profile

Exit Intent Developer Profile

activeconvert

3 plugins · 90 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Exit Intent

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/exit-intent/activeconvert.png
Script Paths
//www.activeconvert.com/api/activeconvert.1.0.js

HTML / DOM Fingerprints

CSS Classes
acei_registeracei_registerCompletesicp_noAccountSpan
HTML Comments
<!-- Exit Intent by ActiveConvert (www.activeconvert.com) -->
Data Attributes
data-target="_ac"id="acei_widgetID"id="acei_submit"name="acei_widgetID"name="acei_submit"placeholder="Your API Key"
JS Globals
acei_wid
FAQ

Frequently Asked Questions about Exit Intent