iConvert Promoter Security & Risk Analysis
wordpress.org/plugins/iconvert-promoter๐ A powerful and dynamic WordPress popup toolkit to grow your email list, retain customers, and boost conversions.
Is iConvert Promoter Safe to Use in 2026?
Generally Safe
Score 100/100iConvert Promoter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The iconvert-promoter plugin v1.0.2 presents a mixed security posture. On the positive side, the plugin exhibits strong practices in SQL query execution and output escaping, with a very high percentage of SQL queries using prepared statements and a vast majority of outputs being properly escaped. The absence of recorded vulnerabilities and CVEs is also a significant strength, suggesting a generally well-maintained codebase in terms of known security flaws.
However, the plugin has notable security concerns stemming from its static analysis. The large number of unprotected AJAX handlers (26 out of 27) represents a substantial attack surface, making it vulnerable to unauthorized actions if these handlers can be triggered by unauthenticated users. The presence of the `unserialize` function, a known source of potential vulnerabilities if used with untrusted input, coupled with three critical taint flows with unsanitized paths, indicates a direct risk of code injection or other severe exploits. While no CVEs are recorded, these inherent risks in the code demand attention.
In conclusion, while iconvert-promoter benefits from good SQL and output sanitization practices and a clean vulnerability history, the significant number of unprotected AJAX endpoints and the critical taint flows with unsanitized paths introduce substantial security risks that outweigh its strengths. The potential for unauthorized access and code execution through these vectors requires immediate remediation to improve its overall security posture.
Key Concerns
- Large attack surface without auth
- Critical severity taint flow (3 instances)
- Dangerous function: unserialize
iConvert Promoter Security Vulnerabilities
iConvert Promoter Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
iConvert Promoter Attack Surface
AJAX Handlers 27
REST API Routes 3
WordPress Hooks 45
Maintenance & Trust
iConvert Promoter Maintenance & Trust
Maintenance Signals
Community Trust
iConvert Promoter Alternatives
Popup Builder & Popup Maker for WordPress โ OptinMonster Email Marketing and Lead Generation
optinmonster
๐คฉ Make popups & optin forms to get more email newsletter subscribers, leads, and sales - #1 most popular popup builder plugin! ๐
Leadfox for WordPress
leadfox
Integrate Leadfox tracking code to enable contact synchronisation with a contact lists, forms and enable pop-ups on your WordPress site.
SendPulse โ Popup Builder for Email Optins, Lead Generation, Sticky Bars and Videos
sendpulse-popups
SendPulse Pop-ups plugin for WordPress. Create highly converting and mobile-friendly pop-ups, opt-in forms, exit popups, sticky bars, NPS surveys, etc
Growify
growify-ai
Integrate Growify.ai analytics into your WordPress site effortlessly. Track visits, WooCommerce conversions and form submissions automatically.
Notifal โ Popup Builder & Notification Tool to Grow Email List, Increase Sale & Boost Conversion
notifal
Show Newsletter Form Popups, Discounted Products Notifications, Exit Intent Popups and More to Boost Conversion. ๐ Unlimited Impressions!
iConvert Promoter Developer Profile
59 plugins ยท 429K total installs
How We Detect iConvert Promoter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/iconvert-promoter/css/dist/style.min.css/wp-content/plugins/iconvert-promoter/js/select2/js/select2.min.js/wp-content/plugins/iconvert-promoter/js/select2/css/select2.min.css/wp-content/plugins/iconvert-promoter/js/snackbar/js-snackbar.min.js/wp-content/plugins/iconvert-promoter/js/snackbar/js-snackbar.css/wp-content/plugins/iconvert-promoter/js/dist/index.js/wp-content/plugins/iconvert-promoter/js/popper/popper.min.js/wp-content/plugins/iconvert-promoter/js/bootstrap/bootstrap.bundle.min.js+3 more/wp-content/plugins/iconvert-promoter/js/select2/js/select2.min.js/wp-content/plugins/iconvert-promoter/js/snackbar/js-snackbar.min.js/wp-content/plugins/iconvert-promoter/js/dist/index.js/wp-content/plugins/iconvert-promoter/js/popper/popper.min.js/wp-content/plugins/iconvert-promoter/js/bootstrap/bootstrap.bundle.min.js/wp-content/plugins/iconvert-promoter/js/bootstrap/bootbox.min.jsiconvert-promoter/css/dist/style.min.css?ver=iconvert-promoter/js/select2/js/select2.min.js?ver=iconvert-promoter/js/select2/css/select2.min.css?ver=iconvert-promoter/js/snackbar/js-snackbar.min.js?ver=iconvert-promoter/js/snackbar/js-snackbar.css?ver=iconvert-promoter/js/dist/index.js?ver=iconvert-promoter/js/popper/popper.min.js?ver=iconvert-promoter/js/bootstrap/bootstrap.bundle.min.js?ver=iconvert-promoter/js/bootstrap/bootbox.min.js?ver=iconvert-promoter/js/bootstrap/css/bootstrap.min.css?ver=iconvert-promoter/js/bootstrap/css/bootstrap-icons.css?ver=HTML / DOM Fingerprints
iconvertpr-promoter-wrapperdata-iconvertpr-idcs_promo_settings