
PopPop Security & Risk Analysis
wordpress.org/plugins/poppopEasily display your widgets inside modal and popup windows.
Is PopPop Safe to Use in 2026?
Generally Safe
Score 85/100PopPop has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "poppop" plugin v0.4 presents a significant security risk due to its unprotected AJAX handlers. While the plugin demonstrates good practices by avoiding dangerous functions, file operations, external HTTP requests, and using prepared statements for SQL queries, the presence of two AJAX handlers without any authentication or capability checks is a major concern. This allows any user, regardless of their role, to trigger these actions, potentially leading to unintended consequences or exploitation.
The static analysis reveals a small attack surface, but the critical weakness lies in the lack of security measures on these entry points. The low percentage of properly escaped output also indicates a risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data might be rendered directly in the browser without proper sanitization. The absence of any recorded vulnerability history is positive, but it does not negate the immediate risks identified in the code. Developers should prioritize implementing nonce checks and capability checks on the AJAX handlers and ensure all output is properly escaped to mitigate these vulnerabilities.
Key Concerns
- AJAX handlers without auth checks
- Low percentage of properly escaped output
PopPop Security Vulnerabilities
PopPop Code Analysis
Output Escaping
PopPop Attack Surface
AJAX Handlers 2
WordPress Hooks 9
Maintenance & Trust
PopPop Maintenance & Trust
Maintenance Signals
Community Trust
PopPop Alternatives
Popup Box – Create Countdown, Coupon, Video, Contact Form Popups
ays-popup-box
Build flexible popups and modal windows with multiple popup types, triggers, and display controls.
Pop-up
pop-up-pop-up
Pop-up Popups
Modal Popup Box: A Flexible Pop Up Box Builder
modal-popup-box
Create and manage a customizable pop up box on your WordPress website. Embed anything from videos and images to forms and shortcodes.
MakeITeasy Popup
makeiteasy-popup
Advanced block based pop-up solution.
Modal Maker – An Elementor Modal Widget
modal-maker
An Elementor widget plugin which adds a customizable button that triggers a modal popup, perfect for displaying additional content or options in a sty …
PopPop Developer Profile
24 plugins · 4K total installs
How We Detect PopPop
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/poppop/js/poppop.js/wp-content/plugins/poppop/css/poppop.css/wp-content/plugins/poppop/js/rokbox.js/wp-content/plugins/poppop/js/poppop.js/wp-content/plugins/poppop/js/rokbox.jspoppop/css/poppop.css?ver=poppop/js/poppop.js?ver=poppop/js/rokbox.js?ver=HTML / DOM Fingerprints
poppop-wrapperpoppop-containerpoppop-contentpoppop-close<!-- before_title --><!-- after_title -->data-poppop-iddata-poppop-auto-firedata-poppop-cookiePoppop/wp-json/poppop/v1/save_cookie