Popslide PRO – popup alternative Security & Risk Analysis

wordpress.org/plugins/popslide

Popslide is better WordPress popup plugin which displays fully customisable bar whereever you want.

100 active installs v3.0 PHP + WP 3.6+ Updated Dec 30, 2016
conversioncookienewsletterpopslidepopup
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Popslide PRO – popup alternative Safe to Use in 2026?

Generally Safe

Score 85/100

Popslide PRO – popup alternative has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The static analysis of the popslide plugin v3.0 reveals a generally positive security posture with several good practices in place. Notably, there are no identified dangerous functions, all SQL queries are properly prepared, and there are no external HTTP requests or file operations, which significantly reduces the attack surface. The plugin also has a clean vulnerability history with zero known CVEs, suggesting a history of secure development.

However, a significant concern arises from the complete lack of output escaping across all identified outputs. This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data or dynamic content is not being sanitized before being displayed. While the plugin has a low number of entry points and checks for nonces, the absence of capability checks on AJAX handlers and the lack of any taint analysis results leave potential blind spots. The plugin's overall security is hampered by this critical oversight in output sanitization, which could easily lead to severe security breaches if exploited.

In conclusion, while the popslide plugin v3.0 benefits from a clean vulnerability record and good practices in areas like SQL handling and external requests, the pervasive lack of output escaping is a critical weakness. This oversight, combined with the absence of capability checks on AJAX handlers and the lack of taint analysis, creates a significant risk for XSS vulnerabilities. A strong emphasis on implementing proper output sanitization is paramount for improving the plugin's security.

Key Concerns

  • No output escaping found
  • No capability checks on AJAX handlers
  • No taint analysis performed
Vulnerabilities
None known

Popslide PRO – popup alternative Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Popslide PRO – popup alternative Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
37
0 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped37 total outputs
Attack Surface

Popslide PRO – popup alternative Attack Surface

Entry Points4
Unprotected0

AJAX Handlers 3

authwp_ajax_popslide_ajax_save_formbackend.php:18
authwp_ajax_popslide_getfrontend.php:23
noprivwp_ajax_popslide_getfrontend.php:24

Shortcodes 1

[wysija_form] frontend.php:97
WordPress Hooks 6
actionadmin_menubackend.php:16
actionwp_enqueue_scriptsfrontend.php:19
actionwp_headfrontend.php:20
actionadmin_noticespopslide.php:36
actionnetwork_admin_noticespopslide.php:37
actionplugins_loadedpopslide.php:74
Maintenance & Trust

Popslide PRO – popup alternative Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.32
Last updatedDec 30, 2016
PHP min version
Downloads12K

Community Trust

Rating100/100
Number of ratings18
Active installs100
Developer Profile

Popslide PRO – popup alternative Developer Profile

Kuba Mikita

9 plugins · 51K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
237 days
View full developer profile
Detection Fingerprints

How We Detect Popslide PRO – popup alternative

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/popslide/assets/css/style.css/wp-content/plugins/popslide/assets/js/admin.js/wp-content/plugins/popslide/assets/js/codemirror.js/wp-content/plugins/popslide/assets/js/codemirror_css.js
Script Paths
/wp-content/plugins/popslide/assets/js/admin.js/wp-content/plugins/popslide/assets/js/codemirror.js/wp-content/plugins/popslide/assets/js/codemirror_css.js

HTML / DOM Fingerprints

CSS Classes
popslide-navnav-tab-active
Data Attributes
data-popslide-target
JS Globals
popslide_vars
FAQ

Frequently Asked Questions about Popslide PRO – popup alternative