
HollerBox — Fast & Effective Popups & Lead-Generation Security & Risk Analysis
wordpress.org/plugins/holler-boxGet more leads and sales with effective popups that convert! Integrate HollerBox with your favorite CRM and email marketing tools.
Is HollerBox — Fast & Effective Popups & Lead-Generation Safe to Use in 2026?
Generally Safe
Score 99/100HollerBox — Fast & Effective Popups & Lead-Generation has a strong security track record. Known vulnerabilities have been patched promptly.
The Holler Box plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for a significant portion of its SQL queries and properly escaping the majority of its output. The absence of dangerous functions and bundled libraries is also a strength. However, there are notable areas of concern, particularly regarding its attack surface. A substantial number of REST API routes lack permission callbacks, creating a wide entry point for potential unauthorized access or manipulation. Furthermore, the taint analysis, while not revealing critical or high severity issues, did identify flows with unsanitized paths, indicating potential vulnerabilities if specific input is not handled carefully.
Key Concerns
- REST API routes without permission callbacks
- AJAX handlers without auth checks
- Flows with unsanitized paths
- Vulnerability history: Medium severity XSS/SQLi
HollerBox — Fast & Effective Popups & Lead-Generation Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
HollerBox <= 2.3.2 - Authenticated (Administrator+) Stored Cross-Site Scripting
HollerBox <= 2.1.3 - Authenticated (edit_popups+) SQL Injection
HollerBox — Fast & Effective Popups & Lead-Generation Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
HollerBox — Fast & Effective Popups & Lead-Generation Attack Surface
AJAX Handlers 1
REST API Routes 13
WordPress Hooks 36
Scheduled Events 1
Maintenance & Trust
HollerBox — Fast & Effective Popups & Lead-Generation Maintenance & Trust
Maintenance Signals
Community Trust
HollerBox — Fast & Effective Popups & Lead-Generation Alternatives
Popup Builder & Popup Maker for WordPress – OptinMonster Email Marketing and Lead Generation
optinmonster
🤩 Make popups & optin forms to get more email newsletter subscribers, leads, and sales - #1 most popular popup builder plugin! 🚀
Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder
popup-maker
Want to boost sales & marketing efforts? Use your favorite forms & builder. Unlimited popups & impressions, keep your data, no monthly subscription.
Advanced Popups
advanced-popups
Display high-converting newsletter popups, a cookie notice, or a notification with the light-weight yet feature-rich plugin.
WebToffee eCommerce Marketing Automation – Email marketing, Popups, Email customizer
decorator-woocommerce-email-customizer
Create and send marketing emails and campaigns. Enable email automations, Popups, spin-a-wheel, sign-up forms, and more. Customize WooCommerce emails.
Easy Notify Lite
easy-notify-lite
The best Popup Builder plugin to display image, video, notify or announcement with very ease and elegant.
HollerBox — Fast & Effective Popups & Lead-Generation Developer Profile
7 plugins · 6K total installs
How We Detect HollerBox — Fast & Effective Popups & Lead-Generation
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/holler-box/assets/css/holler-box.css/wp-content/plugins/holler-box/assets/js/holler-box.js/wp-content/plugins/holler-box/assets/js/holler-box-admin.js/wp-content/plugins/holler-box/assets/js/holler-box.js/wp-content/plugins/holler-box/assets/js/holler-box-admin.jsholler-box/assets/css/holler-box.css?ver=holler-box/assets/js/holler-box.js?ver=holler-box/assets/js/holler-box-admin.js?ver=HTML / DOM Fingerprints
hollerbox-wrapperhollerbox-overlayhollerbox-popuphollerbox-closedata-hollerbox-idHollerBoxholler_box_params/wp-json/hollerbox/v1/popup/wp-json/hollerbox/v1/conversion