
Notifal – Popup Builder & Notification Tool to Grow Email List, Increase Sale & Boost Conversion Security & Risk Analysis
wordpress.org/plugins/notifalShow Newsletter Form Popups, Discounted Products Notifications, Exit Intent Popups and More to Boost Conversion. 🚀 Unlimited Impressions!
Is Notifal – Popup Builder & Notification Tool to Grow Email List, Increase Sale & Boost Conversion Safe to Use in 2026?
Generally Safe
Score 100/100Notifal – Popup Builder & Notification Tool to Grow Email List, Increase Sale & Boost Conversion has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "notifal" v2.1.0 plugin exhibits a mixed security posture. On the positive side, it has no recorded CVEs and a history free of known vulnerabilities, suggesting a generally stable codebase. The plugin also shows good practices in its use of prepared statements for SQL queries (88%) and proper output escaping (84%), along with a reasonable number of nonce and capability checks. However, a significant concern is the large attack surface exposed without adequate authentication or permission checks. A substantial 45 out of 57 entry points, including a high number of AJAX handlers and REST API routes, lack these critical security measures. While no critical taint flows were identified, the presence of unsanitized paths in 6 out of 14 analyzed flows, combined with the large number of unprotected entry points, presents a substantial risk of potential unauthorized access or code execution vulnerabilities. The single use of `preg_replace` with the `/e` modifier is also a critical red flag, as this function is deprecated due to its potential for arbitrary code execution when used with user-supplied input.
Key Concerns
- Numerous unprotected AJAX handlers
- Numerous unprotected REST API routes
- Unsanitized paths in taint flows
- Dangerous preg_replace(/e) function used
Notifal – Popup Builder & Notification Tool to Grow Email List, Increase Sale & Boost Conversion Security Vulnerabilities
Notifal – Popup Builder & Notification Tool to Grow Email List, Increase Sale & Boost Conversion Release Timeline
Notifal – Popup Builder & Notification Tool to Grow Email List, Increase Sale & Boost Conversion Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Notifal – Popup Builder & Notification Tool to Grow Email List, Increase Sale & Boost Conversion Attack Surface
AJAX Handlers 47
REST API Routes 10
WordPress Hooks 114
Scheduled Events 1
Maintenance & Trust
Notifal – Popup Builder & Notification Tool to Grow Email List, Increase Sale & Boost Conversion Maintenance & Trust
Maintenance Signals
Community Trust
Notifal – Popup Builder & Notification Tool to Grow Email List, Increase Sale & Boost Conversion Alternatives
Popup Builder & Popup Maker for WordPress – OptinMonster Email Marketing and Lead Generation
optinmonster
🤩 Make popups & optin forms to get more email newsletter subscribers, leads, and sales - #1 most popular popup builder plugin! 🚀
Themify Popup
themify-popup
Turn visitors into subscribers and increase sale conversions! Use Popup to show newsletter forms, promotions, or lightbox content.
Hello Bar Popup Builder: Design Engaging Popups on WordPress
hellobar
Easily add a Popup to your WordPress site with the official HelloBar WordPress plugin.
Getsitecontrol — Email Marketing Plugin | Popup Maker, Automations & Newsletters
getsitecontrol
Complete email marketing toolset with a powerful popup builder on board. Generate leads with email opt-in forms, send professional newsletters, build …
iConvert Promoter
iconvert-promoter
🚀 A powerful and dynamic WordPress popup toolkit to grow your email list, retain customers, and boost conversions.
Notifal – Popup Builder & Notification Tool to Grow Email List, Increase Sale & Boost Conversion Developer Profile
1 plugin · 60 total installs
How We Detect Notifal – Popup Builder & Notification Tool to Grow Email List, Increase Sale & Boost Conversion
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/notifal/app/Modules/SocialProof/public/assets/css/social-proof.css/wp-content/plugins/notifal/app/Modules/SalesNotification/public/assets/css/sales-notification.css/wp-content/plugins/notifal/app/Modules/SalesNotification/public/assets/js/sales-notification.js/wp-content/plugins/notifal/app/Modules/StockAlert/public/assets/css/stock-alert.css/wp-content/plugins/notifal/app/Modules/StockAlert/public/assets/js/stock-alert.js/wp-content/plugins/notifal/app/Modules/CustomMessage/public/assets/css/custom-message.css/wp-content/plugins/notifal/app/Modules/CustomMessage/public/assets/js/custom-message.js/wp-content/plugins/notifal/app/Modules/Offer/public/assets/css/offer.css+3 more/wp-content/plugins/notifal/app/Modules/SocialProof/public/assets/js/social-proof.js/wp-content/plugins/notifal/app/Modules/SalesNotification/public/assets/js/sales-notification.js/wp-content/plugins/notifal/app/Modules/StockAlert/public/assets/js/stock-alert.js/wp-content/plugins/notifal/app/Modules/CustomMessage/public/assets/js/custom-message.js/wp-content/plugins/notifal/app/Modules/Offer/public/assets/js/offer.js/wp-content/plugins/notifal/app/Modules/Widget/public/assets/js/widget.jsnotifal/app/Modules/SocialProof/public/assets/css/social-proof.css?ver=notifal/app/Modules/SocialProof/public/assets/js/social-proof.js?ver=notifal/app/Modules/SalesNotification/public/assets/css/sales-notification.css?ver=notifal/app/Modules/SalesNotification/public/assets/js/sales-notification.js?ver=notifal/app/Modules/StockAlert/public/assets/css/stock-alert.css?ver=notifal/app/Modules/StockAlert/public/assets/js/stock-alert.js?ver=notifal/app/Modules/CustomMessage/public/assets/css/custom-message.css?ver=notifal/app/Modules/CustomMessage/public/assets/js/custom-message.js?ver=notifal/app/Modules/Offer/public/assets/css/offer.css?ver=notifal/app/Modules/Offer/public/assets/js/offer.js?ver=notifal/app/Modules/Widget/public/assets/css/widget.css?ver=notifal/app/Modules/Widget/public/assets/js/widget.js?ver=HTML / DOM Fingerprints
notifal-widgetnotifal-social-proofnotifal-sales-notificationnotifal-stock-alertnotifal-custom-messagenotifal-offerdata-notifal-iddata-notifal-typeNotifal