Flash Popup Builder Security & Risk Analysis

wordpress.org/plugins/flash-popup-builder

Flash Popup Builder : A simple popup builder plugin with pre-built templates.

0 active installs v1.0.3 PHP 7.2+ WP 5.2+ Updated Sep 9, 2025
email-pop-upemail-subscriptionexit-intentpopup-builderpopups
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Flash Popup Builder Safe to Use in 2026?

Generally Safe

Score 100/100

Flash Popup Builder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8mo ago
Risk Assessment

The plugin "flash-popup-builder" v1.0.3 exhibits a generally good security posture based on the provided static analysis. There are no critical or high severity taint flows, a high percentage of properly escaped outputs, and sufficient nonce and capability checks for its identified entry points. The absence of any known vulnerabilities in its history further suggests a focus on secure development practices. The plugin also avoids bundled libraries, which can often become outdated and introduce risks.

However, there are a couple of areas that warrant attention. The presence of raw SQL queries without the use of prepared statements is a significant concern. This could potentially lead to SQL injection vulnerabilities if user-supplied data is not meticulously sanitized before being used in these queries. While the static analysis did not identify any unsanitized paths in taint flows, this omission is still a considerable risk given the nature of raw SQL. The plugin also performs file operations and external HTTP requests, which, while not inherently insecure, are entry points that require careful consideration for potential abuse if not properly secured.

In conclusion, "flash-popup-builder" v1.0.3 has strengths in its low attack surface with protected entry points, high output escaping, and a clean vulnerability history. The primary weakness lies in the raw SQL queries, which introduce a tangible risk of SQL injection. Addressing this single point of concern would significantly bolster the plugin's overall security.

Key Concerns

  • Raw SQL queries without prepared statements
Vulnerabilities
None known

Flash Popup Builder Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Flash Popup Builder Release Timeline

v1.0.3Current
v1.0.2
v1.0.1
Code Analysis
Analyzed Apr 6, 2026

Flash Popup Builder Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
0 prepared
Unescaped Output
7
217 escaped
Nonce Checks
3
Capability Checks
3
File Operations
1
External Requests
1
Bundled Libraries
0

SQL Query Safety

0% prepared2 total queries

Output Escaping

97% escaped224 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
update_popup_template (admin/prebuilt-templates.php:196)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Flash Popup Builder Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 2

authwp_ajax_update_popup_templateadmin/prebuilt-templates.php:221
noprivwp_ajax_update_popup_templateadmin/prebuilt-templates.php:222

Shortcodes 1

[flash_popup_builder] templates/templates.php:194
WordPress Hooks 15
actionsave_postadmin/includes/edit-popup-temp.php:122
actioninitadmin/prebuilt-templates.php:157
actionadmin_menuadmin/prebuilt-templates.php:160
actionwp_headadmin/prebuilt-templates.php:165
actioninitadmin/prebuilt-templates.php:174
actionadmin_noticesadmin/prebuilt-templates.php:186
actionadmin_enqueue_scriptsflash-popup-builder.php:43
actioninitflash-popup-builder.php:73
actionadmin_menuflash-popup-builder.php:101
actionwp_enqueue_scriptsflash-popup-builder.php:147
actionadmin_enqueue_scriptsflash-popup-builder.php:148
actionadmin_enqueue_scriptsflash-popup-builder.php:185
actionadd_meta_boxesflash-popup-builder.php:199
actionadd_meta_boxesflash-popup-builder.php:215
filterpost_updated_messagesflash-popup-builder.php:235
Maintenance & Trust

Flash Popup Builder Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 9, 2025
PHP min version7.2
Downloads460

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Flash Popup Builder Developer Profile

Themescaliber

29 plugins · 3K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Flash Popup Builder

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/flash-popup-builder/admin/assets/css/style.css/wp-content/plugins/flash-popup-builder/assets/css/style.css/wp-content/plugins/flash-popup-builder/assets/js/custom.js/wp-content/plugins/flash-popup-builder/lib/css/bootstrap.min.css/wp-content/plugins/flash-popup-builder/lib/css/fontawesome-all.min.css/wp-content/plugins/flash-popup-builder/lib/js/bootstrap.bundle.min.js/wp-content/plugins/flash-popup-builder/lib/js/fontawesome-all.min.js/wp-content/plugins/flash-popup-builder/admin/assets/js/script.js+1 more
Script Paths
admin/assets/css/style.cssassets/css/style.cssassets/js/custom.jslib/css/bootstrap.min.csslib/css/fontawesome-all.min.csslib/js/bootstrap.bundle.min.js+3 more
Version Parameters
flash-popup-builder/admin/assets/css/style.css?ver=flash-popup-builder/assets/css/style.css?ver=flash-popup-builder/assets/js/custom.js?ver=flash-popup-builder/lib/css/bootstrap.min.css?ver=flash-popup-builder/lib/css/fontawesome-all.min.css?ver=flash-popup-builder/lib/js/bootstrap.bundle.min.js?ver=flash-popup-builder/lib/js/fontawesome-all.min.js?ver=flash-popup-builder/admin/assets/js/script.js?ver=flash-popup-builder/admin/assets/js/templates-tab.js?ver=

HTML / DOM Fingerprints

CSS Classes
flash-popup-builder-settings
Data Attributes
data-popup-builder-nonce
JS Globals
popup_template_nonceflashPopupBuilderVars
FAQ

Frequently Asked Questions about Flash Popup Builder