
Offer Popup Security & Risk Analysis
wordpress.org/plugins/offers-popupThis plugin lets you add multiple offers with date and URL.
Is Offer Popup Safe to Use in 2026?
Generally Safe
Score 85/100Offer Popup has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "offers-popup" v1.0 plugin exhibits a mixed security posture. On one hand, it boasts a zero attack surface regarding common entry points like AJAX handlers, REST API routes, and shortcodes, and all SQL queries are properly prepared. Furthermore, there are no known vulnerabilities (CVEs) associated with this plugin, suggesting a history of security maintenance or a lack of prior discovery. However, a significant concern arises from the taint analysis, which reveals four flows with unsanitized paths, all classified as high severity. This indicates a substantial risk of data being manipulated or injected by malicious actors. Compounding this, a complete lack of output escaping for all identified outputs is a critical weakness, making stored XSS or other output-based attacks highly probable. While the plugin has a clean vulnerability history and a small, well-contained attack surface, the identified taint flows and universal lack of output escaping present serious, exploitable security risks that need immediate attention.
Key Concerns
- High severity unsanitized taint flows detected
- No output escaping for any output
- No nonce checks implemented
- No capability checks implemented
Offer Popup Security Vulnerabilities
Offer Popup Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Offer Popup Attack Surface
WordPress Hooks 3
Maintenance & Trust
Offer Popup Maintenance & Trust
Maintenance Signals
Community Trust
Offer Popup Alternatives
Announcement & Notification Banner – Bulletin
bulletin-announcements
Publish a slick announcement banner notice across your website or Woocommerce shop. Extend with icons, countdowns, placement rules and more!
AdPlugg WordPress Ad Plugin
adplugg
Advertising is easy with AdPlugg. The AdPlugg WordPress Ad Plugin and ad server allow you to easily manage, schedule, rotate and track your ads.
Name Your Price: Make Your Own Offer for WooCommerce
price-offerings-for-woocommerce
Let customers name their own price on WooCommerce products & donations, offer flexible pricing options with NYOP & open pricing features.
WPSSO Schema Shipping Delivery Time for WooCommerce
wpsso-wc-shipping-delivery-time
Shipping delivery time estimates for WooCommerce shipping zones, methods, and classes.
MobiLoud – Smart App Banners
mobiloud-smart-app-banner
We created this plugin so that you can use Smart App Banners on your WordPress site to boost downloads for your iOS and Android app.
Offer Popup Developer Profile
6 plugins · 110 total installs
How We Detect Offer Popup
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/offers-popup/css/style.css/wp-content/plugins/offers-popup/css/offers.css/wp-content/plugins/offers-popup/js/offers.jsoffers-popup/style.css?ver=offers-popup/css/offers.css?ver=offers-popup/js/offers.js?ver=HTML / DOM Fingerprints
manage_offeroffer_labeloffer_inputoffererror<!-- send a cookie that expires in 2 hours -->name="manage_offer"id="manage_offer"name="offer_name"id="offer_name"name="offer_start"id="offer_start"+10 moreoffersjs<div class="manage_offer"><div class="offer_label">Offer Name</div><div class="offer_input"><div class="offer_label">Offer Start</div>