JSL Exit Intent Popup Security & Risk Analysis

wordpress.org/plugins/jsl-exit-intent-popup

JSL Exit Intent Popup is a simple fully customizable exit intent popup. You should have at least basic knowledge of HTML and CSS.

0 active installs v1.0 PHP 5.2.4+ WP 4.0.1+ Updated May 1, 2020
customizableexit-intent-popupexit-intentsimple
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is JSL Exit Intent Popup Safe to Use in 2026?

Generally Safe

Score 85/100

JSL Exit Intent Popup has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The jsl-exit-intent-popup plugin v1.0 exhibits a generally strong security posture based on the static analysis provided. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points is a significant positive. Furthermore, the plugin demonstrates good practice by utilizing prepared statements for all SQL queries, eliminating the risk of SQL injection through database interactions. The lack of dangerous functions and file operations also contributes to a reduced attack surface.

However, a critical concern arises from the output escaping. With two total outputs analyzed and 0% properly escaped, this indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any dynamic data rendered to the user interface that is not properly escaped can be exploited by attackers to inject malicious scripts, leading to session hijacking, credential theft, or defacement.

The vulnerability history is clean, with no known CVEs recorded. This suggests that, historically, the plugin has not been a source of significant security issues. This, combined with the strong foundation in avoiding common vulnerabilities like SQL injection and the limited attack surface, paints a picture of a plugin that *could* be secure if the output escaping issue is addressed. The primary weakness lies in the unescaped output, which presents a tangible and exploitable risk.

Key Concerns

  • 0% output escaping
Vulnerabilities
None known

JSL Exit Intent Popup Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

JSL Exit Intent Popup Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

JSL Exit Intent Popup Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped2 total outputs
Attack Surface

JSL Exit Intent Popup Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actioncustomize_registerjsl_customizer_settings.php:132
actionwp_enqueue_scriptsjsl_exit_intent_popup.php:22
actionwp_headjsl_exit_intent_popup.php:57
Maintenance & Trust

JSL Exit Intent Popup Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedMay 1, 2020
PHP min version5.2.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

JSL Exit Intent Popup Developer Profile

janiq

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect JSL Exit Intent Popup

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/jsl-exit-intent-popup/js/bioep.min.js
Script Paths
/wp-content/plugins/jsl-exit-intent-popup/js/bioep.min.js
Version Parameters
jsl-exit-intent-popup/js/bioep.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
bio_ep
JS Globals
bioEp
FAQ

Frequently Asked Questions about JSL Exit Intent Popup