
VF Exit Popup your Fast & Secure Exit Popup for WordPress Security & Risk Analysis
wordpress.org/plugins/exit-popup-advancedThe best WordPress contact form plugin. Easy & Fast online form builder that helps you create beautiful contact forms with just a few clicks.
Is VF Exit Popup your Fast & Secure Exit Popup for WordPress Safe to Use in 2026?
Generally Safe
Score 100/100VF Exit Popup your Fast & Secure Exit Popup for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "exit-popup-advanced" v1.0 plugin exhibits a mixed security posture. While the absence of known CVEs, dangerous functions, file operations, external HTTP requests, and bundled libraries are positive indicators, there are significant concerns regarding its attack surface and input sanitization. The plugin exposes three AJAX handlers, with two lacking proper authentication checks. This is a critical weakness as it allows any unauthenticated user to potentially interact with these endpoints, leading to unintended actions or information disclosure.
The code analysis reveals a concerning 33% of SQL queries are not using prepared statements, which, coupled with the lack of comprehensive capability checks and potentially unsanitized inputs (though taint analysis is limited here), increases the risk of SQL injection vulnerabilities. Furthermore, only 56% of output is properly escaped, raising concerns about Cross-Site Scripting (XSS) attacks if user-supplied data is not handled securely before being displayed.
The vulnerability history shows no recorded CVEs, which is a strength. However, this does not guarantee current security, especially in light of the identified weaknesses in the code analysis. The lack of comprehensive taint analysis is also a limitation, as it might not have uncovered deeper, more complex vulnerabilities. In conclusion, while the plugin doesn't have a history of public vulnerabilities and avoids certain risky practices, the unprotected AJAX endpoints and the mixed approach to SQL query preparation and output escaping present notable security risks that require immediate attention.
Key Concerns
- Unprotected AJAX handlers
- SQL queries not using prepared statements
- Output not properly escaped
- Missing capability checks
- Limited taint analysis coverage
VF Exit Popup your Fast & Secure Exit Popup for WordPress Security Vulnerabilities
VF Exit Popup your Fast & Secure Exit Popup for WordPress Code Analysis
SQL Query Safety
Output Escaping
VF Exit Popup your Fast & Secure Exit Popup for WordPress Attack Surface
AJAX Handlers 3
WordPress Hooks 3
Maintenance & Trust
VF Exit Popup your Fast & Secure Exit Popup for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
VF Exit Popup your Fast & Secure Exit Popup for WordPress Alternatives
Exit Popup
exit-popup
Display a jQuery modal window, which can include text, images, videos, forms, maps and so on, before a visitor leaves your website.
Advanced Exit Popup
advanced-exit-popup
Advanced Exit Popup allows you to display custom code like HTML5, Subscription forms, Shortcodes, etc when user intent to exit your website on desktop …
Popup Maker – Responsive popup, Exit Intent Pop up, Email Optins, Autoresponder & More
popup-maker-wp
Popup Maker plugin will help you run cleverer and more effective marketing popups for your website. Create the most optimal popup to boost your sales.
Yeloni Exit Popup | (Free) GDPR Compliance
yeloni-free-exit-popup
Powerful lead generation plugin that converts abandoning visitors into subscribers using exit intent, page level targeting & custom designs.
Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers
popup-builder-block
Powerful Popup Builder Block for Gutenberg block editor.
VF Exit Popup your Fast & Secure Exit Popup for WordPress Developer Profile
7 plugins · 540 total installs
How We Detect VF Exit Popup your Fast & Secure Exit Popup for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/exit-popup-advanced/assets/css/vfep_style.css/wp-content/plugins/exit-popup-advanced/assets/css/fontawesome.css/wp-content/plugins/exit-popup-advanced/assets/js/vfep_main.js/wp-content/plugins/exit-popup-advanced/assets/css/style.css/wp-content/plugins/exit-popup-advanced/assets/js/custom.js/wp-content/plugins/exit-popup-advanced/assets/js/vfep_main.js/wp-content/plugins/exit-popup-advanced/assets/js/custom.jsexit-popup-advanced/assets/js/vfep_main.js?ver=1.0.0exit-popup-advanced/assets/js/custom.js?ver=1.0.0HTML / DOM Fingerprints
ajax_object/wp-json/vfexitpopup/v1/options