Popify – Sales Popups & Social Proof Security & Risk Analysis

wordpress.org/plugins/popify-sales-pop-ups

Popify is the all-in-one tool for creating trust-driven sales and social proof popups that increase engagement and grow conversions.

20 active installs v1.0.7 PHP 5.4+ WP 3.1+ Updated Nov 6, 2025
pop-upsrecent-purchases-orderssales-notificationsales-popsocial-proof
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Popify – Sales Popups & Social Proof Safe to Use in 2026?

Generally Safe

Score 100/100

Popify – Sales Popups & Social Proof has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The static analysis of the "popify-sales-pop-ups" plugin version 1.0.7 indicates a generally good security posture with no immediate critical vulnerabilities identified. The absence of dangerous functions, raw SQL queries, and taint analysis issues is highly positive. Furthermore, the plugin demonstrates a commitment to security by implementing capability checks and properly escaping a significant majority of its output. The plugin also avoids bundled libraries and performs limited external HTTP requests, which reduces its potential attack surface.

However, a notable concern is the complete lack of nonce checks and the absence of any AJAX handlers or REST API routes with proper authentication. While the current version reports zero unprotected entry points, this could indicate that either these functionalities are not yet implemented or are being handled in a way not detectable by the static analysis. The lack of nonce checks, in particular, leaves any AJAX actions susceptible to Cross-Site Request Forgery (CSRF) attacks if they are present but not accounted for. The vulnerability history shows no past issues, which is a strong indicator of responsible development, but the lack of modern security controls like nonces remains a weakness.

Key Concerns

  • Missing nonce checks on AJAX handlers
  • High percentage of unescaped output
Vulnerabilities
None known

Popify – Sales Popups & Social Proof Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Popify – Sales Popups & Social Proof Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
7 escaped
Nonce Checks
0
Capability Checks
3
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

78% escaped9 total outputs
Attack Surface

Popify – Sales Popups & Social Proof Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_enqueue_scriptspopify.php:33
actionadmin_menupopify.php:34
actionwp_headpopify.php:35
Maintenance & Trust

Popify – Sales Popups & Social Proof Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 6, 2025
PHP min version5.4
Downloads5K

Community Trust

Rating60/100
Number of ratings4
Active installs20
Developer Profile

Popify – Sales Popups & Social Proof Developer Profile

importify

4 plugins · 2K total installs

88
trust score
Avg Security Score
100/100
Avg Patch Time
55 days
View full developer profile
Detection Fingerprints

How We Detect Popify – Sales Popups & Social Proof

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/popify-sales-pop-ups/assets/css/style.css/wp-content/plugins/popify-sales-pop-ups/assets/js/script.js
Script Paths
https://app.popify.app/api/js/popifyWoo.js
Version Parameters
popify-sales-pop-ups/assets/css/style.css?ver=popify-sales-pop-ups/assets/js/script.js?ver=

HTML / DOM Fingerprints

Data Attributes
id="popifyScript"id="devpopifyScript"
FAQ

Frequently Asked Questions about Popify – Sales Popups & Social Proof