
Popup with exit intent, scroll triggered and anchor click for opt-ins, lead gen & more Security & Risk Analysis
wordpress.org/plugins/popperA popup builder to increase Sales, Lead Generation, Conversion rates and receive good Call to Action with exit intent.
Is Popup with exit intent, scroll triggered and anchor click for opt-ins, lead gen & more Safe to Use in 2026?
Generally Safe
Score 100/100Popup with exit intent, scroll triggered and anchor click for opt-ins, lead gen & more has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'popper' plugin v0.9.7 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and correctly escaping most of its output. The absence of known CVEs and a clean vulnerability history are also strong indicators of a well-maintained and secure plugin. However, a significant concern arises from its attack surface. There are two AJAX handlers identified, and critically, both lack authentication checks. This creates a direct pathway for unauthenticated users to interact with the plugin's functionality, potentially leading to unintended consequences or exploitation if these handlers are not robustly secured internally.
The static analysis shows no dangerous functions, file operations, or external HTTP requests, which are all positive signs. The taint analysis yielded no concerning flows, further reinforcing the idea that critical, complex vulnerabilities are unlikely to be present. The presence of a nonce check and capability checks on some entry points is also a good sign, though the lack of these on the AJAX handlers is a notable omission.
In conclusion, while the plugin is generally well-coded with good data handling practices and a clean history, the unprotected AJAX endpoints represent a significant security weakness. This oversight could be exploited by attackers to trigger actions within the plugin that were not intended for public access. Addressing these unprotected entry points should be the primary focus for improving the plugin's security.
Key Concerns
- AJAX handlers without authentication checks
- Unescaped output (1 of 6)
Popup with exit intent, scroll triggered and anchor click for opt-ins, lead gen & more Security Vulnerabilities
Popup with exit intent, scroll triggered and anchor click for opt-ins, lead gen & more Code Analysis
SQL Query Safety
Output Escaping
Popup with exit intent, scroll triggered and anchor click for opt-ins, lead gen & more Attack Surface
AJAX Handlers 2
WordPress Hooks 22
Maintenance & Trust
Popup with exit intent, scroll triggered and anchor click for opt-ins, lead gen & more Maintenance & Trust
Maintenance Signals
Community Trust
Popup with exit intent, scroll triggered and anchor click for opt-ins, lead gen & more Alternatives
Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers
popup-builder-block
Powerful Popup Builder Block for Gutenberg block editor.
Popup Builder – Create highly converting, mobile friendly marketing popups.
popup-builder
Increase Sales, Lead Generation, Conversion rates and receive good Call to Action rates with smart WordPress popup plugin.
Popup Box – Create Countdown, Coupon, Video, Contact Form Popups
ays-popup-box
Build flexible popups and modal windows with multiple popup types, triggers, and display controls.
Visual Composer Website Builder
visualcomposer
Drag and drop page builder that gives the freedom to design WordPress websites, landing pages, custom themes, maintenance mode & coming soon pages.
Popup Maker and Popup Anything – Popup for opt-ins and Lead Generation Conversions
popup-anything-on-click
Create popup on a page load or Create popup by clicking link, image and button. Create popups, opt-in forms, & exit popups, floating bars and more!
Popup with exit intent, scroll triggered and anchor click for opt-ins, lead gen & more Developer Profile
5 plugins · 13K total installs
How We Detect Popup with exit intent, scroll triggered and anchor click for opt-ins, lead gen & more
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/popper/build/admin.js/wp-content/plugins/popper/build/style-admin.csspopper/build/admin.js?ver=popper/build/style-admin.css?ver=HTML / DOM Fingerprints
popper-admin-pagepopper-contentpopper-editordata-popper-contentdata-popper-targetdata-popper-placementdata-popper-reference-hiddendata-popper-escapedwindow.popper[popper-content][popper-editor]