
Popup Maker and Popup Anything – Popup for opt-ins and Lead Generation Conversions Security & Risk Analysis
wordpress.org/plugins/popup-anything-on-clickCreate popup on a page load or Create popup by clicking link, image and button. Create popups, opt-in forms, & exit popups, floating bars and more!
Is Popup Maker and Popup Anything – Popup for opt-ins and Lead Generation Conversions Safe to Use in 2026?
Generally Safe
Score 97/100Popup Maker and Popup Anything – Popup for opt-ins and Lead Generation Conversions has a strong security track record. Known vulnerabilities have been patched promptly.
The "popup-anything-on-click" plugin v2.9.1 presents a mixed security posture. While the static analysis reveals a generally good implementation with a high percentage of properly escaped outputs, robust nonce and capability checks, and all SQL queries using prepared statements, there are notable areas of concern. The presence of the `unserialize` dangerous function is a significant red flag, as it can lead to Remote Code Execution if not handled with extreme caution and input validation. Furthermore, the taint analysis indicates two flows with unsanitized paths, which could potentially be exploited for vulnerabilities even if no critical or high severity issues were identified in this specific analysis.
The vulnerability history shows a pattern of medium severity issues, including Missing Authorization, CSRF, and XSS. The fact that there are no currently unpatched CVEs is positive, but the recurring nature of these vulnerability types suggests that the plugin may have historical weaknesses that require continuous vigilance and robust input sanitization. The recent vulnerability in April 2024 indicates that the development team is actively addressing security but also highlights the ongoing need for updates and patching.
Overall, the plugin has strengths in its use of prepared statements and output escaping, but the identified dangerous function and taint flow issues, coupled with its past vulnerability record, necessitate a cautious approach. Users should ensure they are using the latest version and remain aware of potential security updates.
Key Concerns
- Presence of 'unserialize' dangerous function
- Taint analysis shows unsanitized paths (2 flows)
- History of medium severity vulnerabilities (4 total)
Popup Maker and Popup Anything – Popup for opt-ins and Lead Generation Conversions Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
Popup Anything <= 2.8.0 - Missing Authorization
WP OnlineSupport, Essential Plugin Popup Anything <= 2.2.1 - Cross Site Request Forgery
Popup Anything – A Marketing Popup and Lead Generation Conversions <= 2.1.6 - Reflected Cross-Site Scripting
Popup Anything <= 2.0.3 - Contributor+ Stored Cross-Site Scripting
Popup Maker and Popup Anything – Popup for opt-ins and Lead Generation Conversions Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Popup Maker and Popup Anything – Popup for opt-ins and Lead Generation Conversions Attack Surface
AJAX Handlers 2
Shortcodes 2
WordPress Hooks 35
Scheduled Events 1
Maintenance & Trust
Popup Maker and Popup Anything – Popup for opt-ins and Lead Generation Conversions Maintenance & Trust
Maintenance Signals
Community Trust
Popup Maker and Popup Anything – Popup for opt-ins and Lead Generation Conversions Alternatives
Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers
popup-builder-block
Powerful Popup Builder Block for Gutenberg block editor.
Popup Box – Create Countdown, Coupon, Video, Contact Form Popups
ays-popup-box
Build flexible popups and modal windows with multiple popup types, triggers, and display controls.
CartBounty – Save and recover abandoned carts for WooCommerce
woo-save-abandoned-carts
Save abandoned carts and send automated abandoned cart recovery messages. Get more leads, reduce cart abandonment, and increase sales.
FireBox Popups – Increase Sales and Grow Your Email List
firebox
Our WordPress Popup Plugin can help you create any kind of popup! Optin Popups, Exit Popup, Scroll Popup, Page Load Popup, Floating Bars and more!
Popup Maker – Responsive popup, Exit Intent Pop up, Email Optins, Autoresponder & More
popup-maker-wp
Popup Maker plugin will help you run cleverer and more effective marketing popups for your website. Create the most optimal popup to boost your sales.
Popup Maker and Popup Anything – Popup for opt-ins and Lead Generation Conversions Developer Profile
33 plugins · 205K total installs
How We Detect Popup Maker and Popup Anything – Popup for opt-ins and Lead Generation Conversions
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/popup-anything-on-click/assets/css/frontend.css/wp-content/plugins/popup-anything-on-click/assets/js/frontend.js/wp-content/plugins/popup-anything-on-click/assets/js/aoc-public.js/wp-content/plugins/popup-anything-on-click/assets/js/frontend.js/wp-content/plugins/popup-anything-on-click/assets/js/aoc-public.jspopup-anything-on-click/assets/css/frontend.css?ver=popup-anything-on-click/assets/js/frontend.js?ver=popup-anything-on-click/assets/js/aoc-public.js?ver=HTML / DOM Fingerprints
paoc-popup-content-wrapperpaoc-popup-overlaypaoc-popup-closepaoc-popup-containerpaoc-popup-close-icondata-paoc-popup-idpopupaocPopupAnything[popupaoc_popup id=""[paoc_details id="