NertWorks Super Mega Popup Security & Risk Analysis

wordpress.org/plugins/nertworks-super-mega-popup

Super Mega Popup makes it easy to place popups on a particular page, post or site wide. Offers different options for user to select to customize thei …

10 active installs v2.20 PHP + WP 2.0+ Updated Nov 4, 2014
nertworks-pluginspop-pluginpopupsuper-mega-popupwordpress-plugin
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is NertWorks Super Mega Popup Safe to Use in 2026?

Generally Safe

Score 85/100

NertWorks Super Mega Popup has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The "nertworks-super-mega-popup" v2.20 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by having no recorded CVEs, no dangerous functions, and all SQL queries utilizing prepared statements. The absence of external HTTP requests and file operations further reduces its attack surface. However, significant concerns arise from the static analysis. A concerning 0% of its 22 output statements are properly escaped, meaning user-supplied data could be rendered directly in the browser, leading to potential Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the taint analysis reveals two flows with unsanitized paths, although they are not categorized as critical or high severity. The lack of nonce checks and capability checks on its entry points (the single shortcode) is a serious oversight, potentially allowing unauthorized execution of its functionality. The bundled TinyMCE library, while common, could also introduce risks if outdated or vulnerable versions are included.

While the plugin's vulnerability history is clean, the issues identified in the static analysis, particularly the unescaped output and lack of security checks on entry points, represent potential pathways for exploitation. The absence of historical vulnerabilities might be due to the plugin's limited usage or simply a lack of targeted security audits. The plugin's strengths lie in its avoidance of direct database manipulation risks and external dependencies. However, the prevalence of unescaped output and the absence of essential security controls on its shortcode entry point significantly elevate the risk profile and warrant immediate attention. A balanced conclusion is that while the plugin avoids some common pitfalls, critical security gaps exist that could be exploited.

Key Concerns

  • 0% of outputs properly escaped
  • 2 unsanitized path taint flows
  • 0 nonce checks
  • 0 capability checks
  • Bundled library (TinyMCE)
Vulnerabilities
None known

NertWorks Super Mega Popup Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

NertWorks Super Mega Popup Release Timeline

v1.0
Code Analysis
Analyzed Apr 16, 2026

NertWorks Super Mega Popup Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
22
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

TinyMCE

Output Escaping

0% escaped22 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
nertworks_popup_settings_page (nertworks-super-mega-popup.php:179)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

NertWorks Super Mega Popup Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[show_super_mega_popup] nertworks-super-mega-popup.php:108
WordPress Hooks 14
actioninitnertworks-super-mega-popup.php:13
actionwp_footernertworks-super-mega-popup.php:19
actionwp_footernertworks-super-mega-popup.php:24
actionwp_footernertworks-super-mega-popup.php:35
actionwp_footernertworks-super-mega-popup.php:40
actionwp_enqueue_scriptsnertworks-super-mega-popup.php:51
actioninitnertworks-super-mega-popup.php:76
actioninitnertworks-super-mega-popup.php:92
actioninitnertworks-super-mega-popup.php:294
actionwp_enqueue_scriptsnertworks-super-mega-popup.php:603
actionadmin_initnertworks-super-mega-popup.php:628
actionadmin_menunertworks-super-mega-popup.php:629
actionadmin_initnertworks-super-mega-popup.php:652
actionadmin_initnertworks-super-mega-popup.php:665
Maintenance & Trust

NertWorks Super Mega Popup Maintenance & Trust

Maintenance Signals

WordPress version tested4.0.38
Last updatedNov 4, 2014
PHP min version
Downloads8K

Community Trust

Rating70/100
Number of ratings2
Active installs10
Developer Profile

NertWorks Super Mega Popup Developer Profile

nertworks

2 plugins · 30 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect NertWorks Super Mega Popup

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/nertworks-super-mega-popup/inc/colorbox/colorbox.css/wp-content/plugins/nertworks-super-mega-popup/inc/colorbox/jquery.colorbox.js
Script Paths
/wp-content/plugins/nertworks-super-mega-popup/inc/colorbox/jquery.colorbox.js

HTML / DOM Fingerprints

CSS Classes
wrapabout-textnav-tab-wrappernav-tabnav-tab-activegroup
Data Attributes
id="general_settings"id="tools"id="about"id="help"
JS Globals
jQuery$
Shortcode Output
[show_super_mega_popup]<script type='text/javascript'> alert("<script type='text/javascript' src="<link rel="stylesheet" type="text/css" href="
FAQ

Frequently Asked Questions about NertWorks Super Mega Popup