
Page Takeover Security & Risk Analysis
wordpress.org/plugins/page-takeoverCreate a full-screen popup without a developer. Promote your content and offers in a full-screen overlay.
Is Page Takeover Safe to Use in 2026?
Generally Safe
Score 99/100Page Takeover has a strong security track record. Known vulnerabilities have been patched promptly.
The 'page-takeover' plugin v1.1.7 exhibits a generally good security posture based on the provided static analysis. The absence of identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points significantly reduces the potential attack surface. The code also shows positive signs with no dangerous functions identified, all SQL queries utilizing prepared statements, and a high percentage of output escaping. File operations and external HTTP requests are also absent, further limiting attack vectors.
However, a notable concern stems from the vulnerability history. The plugin has had one known CVE in the past, specifically an 'Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)'. While this vulnerability is currently patched, its existence indicates that vulnerabilities can and have occurred. The lack of nonce checks and capability checks, while not directly exploitable due to the limited attack surface in this version, could become a concern if new entry points are introduced in future updates without proper security measures. The zero taint flows with unsanitized paths is a positive sign for this specific version, but it does not negate the past XSS vulnerability.
Key Concerns
- Past XSS vulnerability indicates a potential weakness
- Missing nonce checks
- Missing capability checks
Page Takeover Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Page Takeover <= 1.1.6 - Authenticated (Administrator+) Stored Cross-Site Scripting
Page Takeover Code Analysis
Output Escaping
Page Takeover Attack Surface
WordPress Hooks 7
Maintenance & Trust
Page Takeover Maintenance & Trust
Maintenance Signals
Community Trust
Page Takeover Alternatives
Popup Builder – Create highly converting, mobile friendly marketing popups.
popup-builder
Increase Sales, Lead Generation, Conversion rates and receive good Call to Action rates with smart WordPress popup plugin.
Popup Box – Create Countdown, Coupon, Video, Contact Form Popups
ays-popup-box
Build flexible popups and modal windows with multiple popup types, triggers, and display controls.
Poptin – Exit Pop Ups & Email Popups
poptin
Free exit intent popup builder, gamified popups with spin the wheel, contact form builder & lead generation pop ups platform for your website. 🎉
Pop-up
pop-up-pop-up
Pop-up Popups
Simple Full Screen Background Image
simple-full-screen-background-image
This plugin provides a simple way to set an automatically scaled full screen background image.
Page Takeover Developer Profile
3 plugins · 3K total installs
How We Detect Page Takeover
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/page-takeover/css/page-takeover-admin.css/wp-content/plugins/page-takeover/js/page-takeover-color.js/wp-content/plugins/page-takeover/js/custom.js/wp-content/plugins/page-takeover/js/autosize.jshttps://ajax.googleapis.com/ajax/libs/webfont/1.6.26/webfont.jspage-takeover-admin-css?ver=page-takeover-color.js?ver=custom.js?ver=autosize.js?ver=HTML / DOM Fingerprints
page-takeover-container-leftpage-takeover-container-rightpage-takeover-clearpage-takeover-option-grouppage-takeover-option-widepage-takeover-option-descriptionpage-takeover-admin-notetoggle-wrap+2 moreid="page-takeover"id="frm1"window.WebFont