
Popularis Extra Security & Risk Analysis
wordpress.org/plugins/popularis-extraPopularis Extra add extra features to Popularis theme like demo import, widgets, shortcodes or Elementor widgets.
Is Popularis Extra Safe to Use in 2026?
Mostly Safe
Score 74/100Popularis Extra is generally safe to use. 3 past CVEs were resolved. Keep it updated.
The 'popularis-extra' plugin v1.2.10 exhibits a mixed security posture. On the positive side, static analysis reveals a robust implementation of security controls, with all identified entry points (AJAX handlers, REST API routes, shortcodes, and cron events) appearing to have authentication or permission checks. SQL queries are consistently prepared, and a significant majority of output is properly escaped, indicating good development practices in these areas. Nonce and capability checks are also prevalent.
However, the presence of the `unserialize` function is a significant concern, as it can lead to remote code execution vulnerabilities if not handled with extreme care and strict input validation. While no critical or high severity taint flows were identified, the three flows with unsanitized paths, even if of lower severity in this analysis, warrant attention and further investigation to ensure they do not expose the application. The plugin's vulnerability history is also a red flag, with three known medium severity CVEs and, most critically, one currently unpatched vulnerability. The historical pattern of CSRF, authorization bypass, and XSS indicates a recurring tendency for vulnerabilities to emerge in these attack vectors.
In conclusion, while 'popularis-extra' demonstrates strengths in input sanitization and authentication mechanisms for its entry points, the `unserialize` function, unsanitized paths in taint flows, and a history of unpatched vulnerabilities present substantial risks. The single unpatched CVE significantly lowers the plugin's overall security rating. Users should exercise caution and prioritize updating to a version that addresses all known vulnerabilities.
Key Concerns
- Unpatched CVE
- Dangerous function: unserialize
- Flows with unsanitized paths
Popularis Extra Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Popularis Extra <= 1.2.10 - Cross-Site Request Forgery
Popularis Extra <= 1.2.7 - Authenticated (Contributor+) Post Disclosure
Popularis Extra <= 1.2.6 - Reflected Cross-Site Scripting
Popularis Extra Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Popularis Extra Attack Surface
AJAX Handlers 8
Shortcodes 1
WordPress Hooks 36
Scheduled Events 2
Maintenance & Trust
Popularis Extra Maintenance & Trust
Maintenance Signals
Community Trust
Popularis Extra Alternatives
Wishful Companion
wishful-companion
Wishful Companion add extra features to all WishfulThemes themes like demo import and other widgets.
aThemes Starter Sites
athemes-starter-sites
We've got a full and ever-growing library stocked with ready-made templates for any kind of business.
Bosa Elementor Addons and Templates for WooCommerce
bosa-elementor-for-woocommerce
Elementor Addon with widgets and templates for WooCommerce.
Apollo13 Framework Extensions
apollo13-framework-extensions
Adds custom post types, shortcodes and some features that are used in themes built on Apollo13 Framework.
Futurio Extra
futurio-extra
Futurio Extra add extra features to Futurio theme like widgets, WooCommerce options, Elementor widgets, one click demo import and much more.
Popularis Extra Developer Profile
14 plugins · 26K total installs
How We Detect Popularis Extra
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/popularis-extra/assets/css/admin.css/wp-content/plugins/popularis-extra/assets/css/responsive.css/wp-content/plugins/popularis-extra/assets/js/admin.js/wp-content/plugins/popularis-extra/assets/js/script.js/wp-content/plugins/popularis-extra/assets/css/style.css/wp-content/plugins/popularis-extra/assets/js/admin.js/wp-content/plugins/popularis-extra/assets/js/script.jspopularis-extra/assets/css/admin.css?ver=popularis-extra/assets/css/responsive.css?ver=popularis-extra/assets/js/admin.js?ver=popularis-extra/assets/js/script.js?ver=popularis-extra/assets/css/style.css?ver=HTML / DOM Fingerprints
popularis-extra-settingsPopularis Extra Settingsdata-popularis-extra-colordata-popularis-extra-backgroundpopularis_extra_settings