
Modal Window – create popup modal window Security & Risk Analysis
wordpress.org/plugins/modal-windowWordPress popup plugin for easily creating a popup and modal window with any kind of content and settings.
Is Modal Window – create popup modal window Safe to Use in 2026?
Generally Safe
Score 96/100Modal Window – create popup modal window has a strong security track record. Known vulnerabilities have been patched promptly.
The 'modal-window' plugin v6.2.4 exhibits a mixed security posture. While it demonstrates strong practices in output escaping (98%) and makes good use of prepared statements for SQL queries (77%), several concerns warrant attention. The presence of a dangerous function (`preg_replace(/e)`) is a significant red flag, as this can be a common vector for remote code execution if not handled with extreme care. Furthermore, the taint analysis reveals three high-severity flows with unsanitized paths, indicating potential for data leakage or manipulation if these paths are exploited. The plugin's history of 7 CVEs, including one high-severity vulnerability type (Cross-Site Scripting) and others related to CSRF, suggests a past tendency towards input validation and authorization weaknesses, though it's positive that there are currently no unpatched CVEs.
Key Concerns
- Dangerous function: preg_replace(/e) present
- High severity taint flows (3)
- History of high severity CVEs
- History of medium severity CVEs (6)
- Vulnerability last recorded 2025-02-19
Modal Window – create popup modal window Security Vulnerabilities
CVEs by Year
Severity Breakdown
7 total CVEs
Modal Window <= 6.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via iframeBox Shortcode
Modal Window <= 6.1.4 - Cross-Site Request Forgery to Settings Ipdate
Modal Window <= 6.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
Modal Window – create popup modal window <= 5.3.9 - Cross-Site Request Forgery
Modal Window – create popup modal window <= 5.3.8 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode
Modal Window <= 5.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Modal Window – create popup modal window <= 5.2.1 - Cross-Site Request Forgery to Remote Code Execution
Modal Window – create popup modal window Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Modal Window – create popup modal window Attack Surface
AJAX Handlers 1
Shortcodes 6
WordPress Hooks 13
Maintenance & Trust
Modal Window – create popup modal window Maintenance & Trust
Maintenance Signals
Community Trust
Modal Window – create popup modal window Alternatives
WP Popup
wp-pop-up
Looking for a new way to entice your site visitors? WP Popup is the lightbox/popup plugin built with performance in mind.
PWP Lytebox
pwp-lytebox
The fast and simple way to make all links pointing to images open in popup modal window.
Lightbox & Modal Popup WordPress Plugin – FooBox
foobox-image-lightbox
A responsive image lightbox for WordPress galleries, WordPress attachments & FooGallery
Popup Maker and Popup Anything – Popup for opt-ins and Lead Generation Conversions
popup-anything-on-click
Create popup on a page load or Create popup by clicking link, image and button. Create popups, opt-in forms, & exit popups, floating bars and more!
Ocean Modal Window
ocean-modal-window
Create the good kind of popups with ease and display anywhere on your website!
Modal Window – create popup modal window Developer Profile
25 plugins · 98K total installs
How We Detect Modal Window – create popup modal window
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/modal-window/admin/css/bootstrap-grid.css/wp-content/plugins/modal-window/admin/css/style.css/wp-content/plugins/modal-window/admin/js/bootstrap.bundle.js/wp-content/plugins/modal-window/admin/js/modal-admin.js/wp-content/plugins/modal-window/public/css/modal.css/wp-content/plugins/modal-window/public/js/modal-public.jsmodal-window/admin/css/bootstrap-grid.css?ver=modal-window/admin/css/style.css?ver=modal-window/admin/js/bootstrap.bundle.js?ver=modal-window/admin/js/modal-admin.js?ver=modal-window/public/css/modal.css?ver=modal-window/public/js/modal-public.js?ver=HTML / DOM Fingerprints
modal-window-bodymodal-window-closemodal-window-contentmodal-window-footermodal-window-headermodal-window-overlaymodal-window-wrapperwow-modal-windows-pro+2 more<!-- Main admin section --><!-- End Main admin section --><!-- Preview content section --><!-- End Preview content section -->+12 moredata-bs-toggledata-bs-targetdata-modal-window-iddata-modal-closedata-modal-overlayWOWP_PluginModalWindowmodal_window_preview_contentmodal_adminmodal_public/wp-json/modal-window/v1/preview[Modal-Window]