
Popup addon for Ninja Forms Security & Risk Analysis
wordpress.org/plugins/popup-addon-for-ninja-formsPopup/Modal addon for Ninja Forms. Create beautiful popups using Ninja Forms for newsletters, login, registration forms.
Is Popup addon for Ninja Forms Safe to Use in 2026?
Generally Safe
Score 98/100Popup addon for Ninja Forms has a strong security track record. Known vulnerabilities have been patched promptly.
The 'popup-addon-for-ninja-forms' plugin v3.5.2 presents a mixed security posture. While it demonstrates good practices such as using prepared statements for all SQL queries and implementing nonce and capability checks on some entry points, significant concerns remain regarding output escaping and historical vulnerabilities. The static analysis reveals that a substantial portion of output (55%) is not properly escaped, indicating a potential risk of Cross-Site Scripting (XSS) vulnerabilities. Despite the absence of critical or high severity taint flows in this analysis, the history of two medium severity XSS vulnerabilities, with the last occurring in late 2025, suggests a recurring pattern of input sanitization issues. The lack of unpatched CVEs is positive, but the ongoing presence of medium severity issues in the past warrants attention. The plugin has a small attack surface with only one shortcode, and it appears to be protected. However, the unescaped output is the most prominent risk, and the historical trend of XSS vulnerabilities, even if currently patched, suggests a need for more robust input validation and output sanitization.
Key Concerns
- Insufficient output escaping
- History of medium severity XSS vulnerabilities
Popup addon for Ninja Forms Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Popup addon for Ninja Forms <= 3.5.1 - Authenticated (Administrator+) Stored Cross-Site Scripting
Popup addon for Ninja Forms <= 3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
Popup addon for Ninja Forms Code Analysis
Output Escaping
Data Flow Analysis
Popup addon for Ninja Forms Attack Surface
Shortcodes 1
WordPress Hooks 20
Maintenance & Trust
Popup addon for Ninja Forms Maintenance & Trust
Maintenance Signals
Community Trust
Popup addon for Ninja Forms Alternatives
Easy Popups – Beautiful, Responsive Popups for Lead Capture & Announcements
easy-popups
Create beautiful, responsive popups in minutes. Add forms, videos, smart triggers, and precise display rules — all inside WordPress.
Result Popups for CF7
result-popups-for-cf7
Modernize your Contact Form 7 messages with clean, customizable SweetAlert2 popups. No config needed. Just activate and enjoy.
Asap – Popups Studio
asap-popups-studio
Create and manage multiple custom popups with individual settings and display rules.
Creative Mail – Easier WordPress & WooCommerce Email Marketing
creative-mail-by-constant-contact
Creative Mail was designed specifically for WordPress and WooCommerce. Our intelligent (and super fun) email editor simplifies email marketing campaig …
Lightbox & Modal Popup WordPress Plugin – FooBox
foobox-image-lightbox
A responsive image lightbox for WordPress galleries, WordPress attachments & FooGallery
Popup addon for Ninja Forms Developer Profile
11 plugins · 8K total installs
How We Detect Popup addon for Ninja Forms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/popup-addon-for-ninja-forms/css/animations.css/wp-content/plugins/popup-addon-for-ninja-forms/css/magnific-popup.css/wp-content/plugins/popup-addon-for-ninja-forms/js/magnific-popup.js/wp-content/plugins/popup-addon-for-ninja-forms/js/nf-popups.js/wp-content/plugins/popup-addon-for-ninja-forms/css/nf-popups-admin.css/wp-content/plugins/popup-addon-for-ninja-forms/js/admin.js/wp-content/plugins/popup-addon-for-ninja-forms/js/customizer-preview.js/wp-content/plugins/popup-addon-for-ninja-forms/js/magnific-popup.js/wp-content/plugins/popup-addon-for-ninja-forms/js/nf-popups.js/wp-content/plugins/popup-addon-for-ninja-forms/js/admin.js/wp-content/plugins/popup-addon-for-ninja-forms/js/customizer-preview.jsHTML / DOM Fingerprints
nf-popups-close-btnnf_popup_id_customizernf_popup_id_customizer