Flatsome pop-up element Security & Risk Analysis

wordpress.org/plugins/pop-up-element-for-flatsome-theme

Add custom pop-up element for Flatsome theme for advertisment

100 active installs v1.0.0 PHP 7.0+ WP 4.7+ Updated May 3, 2019
advertismentflatsomeflatsome-popuppop-uppopup
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Flatsome pop-up element Safe to Use in 2026?

Generally Safe

Score 85/100

Flatsome pop-up element has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The plugin "pop-up-element-for-flatsome-theme" v1.0.0 exhibits a seemingly strong security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests are positive indicators. Furthermore, the plugin does not appear to bundle any external libraries, which can often be a source of vulnerabilities. The lack of known CVEs and a clean vulnerability history further contribute to a positive initial assessment.

However, several areas raise concerns. The extremely low percentage of properly escaped output (7%) is a significant red flag. This suggests that user-supplied data or dynamic content being displayed by the plugin is likely not being properly sanitized, creating a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. The complete lack of nonce checks and capability checks across all entry points (though the attack surface is small with only one shortcode) means that even if an attacker cannot directly inject malicious code, they could potentially trigger actions or display sensitive information without proper authorization or verification.

While the plugin has no known vulnerabilities, the identified code signals regarding output escaping and the absence of security checks on its single entry point present a clear and present danger. The low percentage of proper output escaping is the most critical concern, indicating a high likelihood of XSS. This, combined with the lack of authorization checks, means that despite a clean history, the plugin is not defensively programmed and leaves significant room for exploitation.

Key Concerns

  • Low percentage of properly escaped output
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

Flatsome pop-up element Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Flatsome pop-up element Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
14
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

7% escaped15 total outputs
Attack Surface

Flatsome pop-up element Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[ux_fvn_popup] index.php:392
WordPress Hooks 1
actionux_builder_setupindex.php:255
Maintenance & Trust

Flatsome pop-up element Maintenance & Trust

Maintenance Signals

WordPress version tested5.1.22
Last updatedMay 3, 2019
PHP min version7.0
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

Flatsome pop-up element Developer Profile

Freelancerviet.net

1 plugin · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Flatsome pop-up element

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/pop-up-element-for-flatsome-theme/fvn-popup.css/wp-content/plugins/pop-up-element-for-flatsome-theme/fvn-popup.js
Script Paths
/wp-content/plugins/pop-up-element-for-flatsome-theme/fvn-popup.js
Version Parameters
pop-up-element-for-flatsome-theme/fvn-popup.css?ver=pop-up-element-for-flatsome-theme/fvn-popup.js?ver=

HTML / DOM Fingerprints

CSS Classes
fvn-popupbox-image-innerbox-imagebox-textbox-text-topbox-text-middlebox-text-bottomtext-left+7 more
Data Attributes
data-fvn-popup-id
JS Globals
fvn_popup_script
Shortcode Output
[ux_fvn_popup][/ux_fvn_popup]
FAQ

Frequently Asked Questions about Flatsome pop-up element