
NertWorks Super Mega Popup Security & Risk Analysis
wordpress.org/plugins/nertworks-super-mega-popupSuper Mega Popup makes it easy to place popups on a particular page, post or site wide. Offers different options for user to select to customize thei …
Is NertWorks Super Mega Popup Safe to Use in 2026?
Generally Safe
Score 85/100NertWorks Super Mega Popup has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "nertworks-super-mega-popup" v2.20 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by having no recorded CVEs, no dangerous functions, and all SQL queries utilizing prepared statements. The absence of external HTTP requests and file operations further reduces its attack surface. However, significant concerns arise from the static analysis. A concerning 0% of its 22 output statements are properly escaped, meaning user-supplied data could be rendered directly in the browser, leading to potential Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the taint analysis reveals two flows with unsanitized paths, although they are not categorized as critical or high severity. The lack of nonce checks and capability checks on its entry points (the single shortcode) is a serious oversight, potentially allowing unauthorized execution of its functionality. The bundled TinyMCE library, while common, could also introduce risks if outdated or vulnerable versions are included.
While the plugin's vulnerability history is clean, the issues identified in the static analysis, particularly the unescaped output and lack of security checks on entry points, represent potential pathways for exploitation. The absence of historical vulnerabilities might be due to the plugin's limited usage or simply a lack of targeted security audits. The plugin's strengths lie in its avoidance of direct database manipulation risks and external dependencies. However, the prevalence of unescaped output and the absence of essential security controls on its shortcode entry point significantly elevate the risk profile and warrant immediate attention. A balanced conclusion is that while the plugin avoids some common pitfalls, critical security gaps exist that could be exploited.
Key Concerns
- 0% of outputs properly escaped
- 2 unsanitized path taint flows
- 0 nonce checks
- 0 capability checks
- Bundled library (TinyMCE)
NertWorks Super Mega Popup Security Vulnerabilities
NertWorks Super Mega Popup Release Timeline
NertWorks Super Mega Popup Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
NertWorks Super Mega Popup Attack Surface
Shortcodes 1
WordPress Hooks 14
Maintenance & Trust
NertWorks Super Mega Popup Maintenance & Trust
Maintenance Signals
Community Trust
NertWorks Super Mega Popup Alternatives
Elegant Subscription Popup
elegant-subscription-popup
Elegant Subscription Popup is the most popular lead capturing wordpress plugin (7000+ downloads) that helps to convert your visitors to subscribers, t …
Stylish Notification Popup
stylish-notification-popup
Stylish Notification Popup is a responsive popup plugin for wordpress to show attention grabbing message to your visitors with call to action button a …
Show and Link Bible Verse
show-and-link-bible-verse
Converts Bible references into interactive links with an option to display full verses in a popup
Popup Builder & Popup Maker for WordPress – OptinMonster Email Marketing and Lead Generation
optinmonster
🤩 Make popups & optin forms to get more email newsletter subscribers, leads, and sales - #1 most popular popup builder plugin! 🚀
Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder
popup-maker
Want to boost sales & marketing efforts? Use your favorite forms & builder. Unlimited popups & impressions, keep your data, no monthly subscription.
NertWorks Super Mega Popup Developer Profile
2 plugins · 30 total installs
How We Detect NertWorks Super Mega Popup
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/nertworks-super-mega-popup/inc/colorbox/colorbox.css/wp-content/plugins/nertworks-super-mega-popup/inc/colorbox/jquery.colorbox.js/wp-content/plugins/nertworks-super-mega-popup/inc/colorbox/jquery.colorbox.jsHTML / DOM Fingerprints
wrapabout-textnav-tab-wrappernav-tabnav-tab-activegroupid="general_settings"id="tools"id="about"id="help"jQuery$[show_super_mega_popup]<script type='text/javascript'>
alert("<script type='text/javascript' src="<link rel="stylesheet" type="text/css" href="