
ITRO Popup Plugin Security & Risk Analysis
wordpress.org/plugins/itro-popupDisplay a popup to your WordPress site: age verification popup for adult-content site ★ multilanguage popup with qTransalte-X ★ very easy to use
Is ITRO Popup Plugin Safe to Use in 2026?
Generally Safe
Score 85/100ITRO Popup Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "itro-popup" plugin version 5.2.6 exhibits a generally positive security posture based on the provided static analysis. The absence of any known CVEs and a clean vulnerability history is a significant strength, suggesting a mature and well-maintained codebase. Furthermore, the plugin demonstrates good practice in limiting its attack surface with no unprotected AJAX handlers or REST API routes, and a low number of total entry points (one shortcode). The presence of nonce and capability checks, alongside a lack of dangerous function usage and file operations, further bolsters its security. However, there are notable areas for improvement. A significant concern is the low percentage of SQL queries using prepared statements. This practice, coupled with a high volume of SQL queries, could expose the plugin to SQL injection vulnerabilities if not handled with extreme care. Additionally, the exceptionally low rate of proper output escaping is a critical weakness, leaving the plugin vulnerable to Cross-Site Scripting (XSS) attacks. The vast majority of outputs are not properly escaped, which is a severe risk.
While the taint analysis shows no flows with unsanitized paths, this may be due to the limited scope of the analysis or the absence of specific input vectors being tested. The absence of external HTTP requests and bundled libraries is also a positive sign, reducing potential attack vectors. In conclusion, while "itro-popup" version 5.2.6 benefits from a lack of historical vulnerabilities and a controlled attack surface, the significant issues with SQL statement preparation and output escaping represent substantial security risks that require immediate attention. Addressing these weaknesses would greatly improve the plugin's overall security.
Key Concerns
- Low percentage of SQL queries using prepared statements
- Very low rate of proper output escaping
ITRO Popup Plugin Security Vulnerabilities
ITRO Popup Plugin Code Analysis
SQL Query Safety
Output Escaping
ITRO Popup Plugin Attack Surface
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
ITRO Popup Plugin Maintenance & Trust
Maintenance Signals
Community Trust
ITRO Popup Plugin Alternatives
WP Announce
wp-announce
Clean announcement plugin that reveals a neat popup when users visit your site. You can set who sees the announcement and when to display it.
Popups – Submission Messages For Contact Form 7
cf7-popups
Display contact form 7 default messages in stylish popup as user submits the form.
Popup Message Notifier for Contact Form 7
popup-notifier-for-contact-form-7
This plugin will show confirmation and error messages of CF7 inside a popup made with sweetalert2.
Popup Like box – Page Plugin
ays-facebook-popup-likebox
With the help of this amazing plugin you can promote your Facebook page and add number of Likes , which is very important today.
Success Fail Popup Message For Contact Form 7
success-fail-popup-message-for-contact-form-7
Success Fail Popup Message For Contact Form 7 to make the best way to set up poup on success and failed messages so a visitor will be attracted to tha …
ITRO Popup Plugin Developer Profile
23 plugins · 109K total installs
How We Detect ITRO Popup Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/itro-popup/css/itro-admin-style.css/wp-content/plugins/itro-popup/scripts/itro-admin-scripts.js/wp-content/plugins/itro-popup/scripts/itro-scripts.js/wp-content/plugins/itro-popup/scripts/itro-scripts.jsitro-popup/css/itro-admin-style.css?ver=itro-popup/scripts/itro-admin-scripts.js?ver=itro-popup/scripts/itro-scripts.js?ver=HTML / DOM Fingerprints
itro-popupThis file is part of ITRO Popup Plugin. (email : support@itroteam.com)data-ipp-root-pathippRootPathippitroPathippitroImagesITRO_VERpopup_fired