Modal Maker – An Elementor Modal Widget Security & Risk Analysis

wordpress.org/plugins/modal-maker

An Elementor widget plugin which adds a customizable button that triggers a modal popup, perfect for displaying additional content or options in a sty …

100 active installs v1.4 PHP 7.0+ WP 5.0+ Updated Nov 15, 2024
elementormodalpopupwidget
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Modal Maker – An Elementor Modal Widget Safe to Use in 2026?

Generally Safe

Score 92/100

Modal Maker – An Elementor Modal Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the 'modal-maker' plugin v1.4 exhibits a strong security posture. The absence of known CVEs and a clean vulnerability history indicate a history of responsible development and security awareness. The static analysis reveals a remarkably clean codebase with no apparent attack surface through AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, the code demonstrates excellent security practices by utilizing prepared statements for all SQL queries, properly escaping all output, and avoiding dangerous functions and file operations. The lack of any identified taint flows, especially critical or high severity ones, is a significant positive indicator. However, the complete absence of nonce and capability checks across all entry points is a notable concern. While the current lack of identified attack vectors and known vulnerabilities is reassuring, relying solely on the absence of immediate threats without these fundamental security mechanisms can leave the plugin susceptible to future unforeseen vulnerabilities, particularly if its functionality or integration with other plugins changes.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Modal Maker – An Elementor Modal Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Modal Maker – An Elementor Modal Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
14 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped14 total outputs
Attack Surface

Modal Maker – An Elementor Modal Widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionwp_enqueue_scriptsmodal-maker.php:26
actionelementor/widgets/registermodal-maker.php:36
Maintenance & Trust

Modal Maker – An Elementor Modal Widget Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedNov 15, 2024
PHP min version7.0
Downloads843

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

Modal Maker – An Elementor Modal Widget Developer Profile

Sourav Das

1 plugin · 100 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Modal Maker – An Elementor Modal Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/modal-maker/assets/css/my-modal-style.css/wp-content/plugins/modal-maker/assets/js/my-modal-script.js
Script Paths
/wp-content/plugins/modal-maker/assets/js/my-modal-script.js
Version Parameters
modal-maker/assets/css/my-modal-style.css?ver=modal-maker/assets/js/my-modal-script.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Modal Maker – An Elementor Modal Widget