
Popup Box – Easily Create WordPress Popups Security & Risk Analysis
wordpress.org/plugins/popup-boxPopup Box lets you create responsive, customizable WordPress popups with live preview, flexible triggers, and smart targeting to boost engagement and …
Is Popup Box – Easily Create WordPress Popups Safe to Use in 2026?
Generally Safe
Score 95/100Popup Box – Easily Create WordPress Popups has a strong security track record. Known vulnerabilities have been patched promptly.
The 'popup-box' plugin version 3.2.14 exhibits a mixed security posture. On the positive side, it demonstrates good practices by having all identified entry points (AJAX handlers, shortcodes) protected by nonce and capability checks, and a high percentage of SQL queries utilize prepared statements, with an even higher percentage of output being properly escaped. File operations and external HTTP requests are absent, which reduces the attack surface. However, the static analysis reveals a concerning finding: 100% of the analyzed taint flows have unsanitized paths. While no critical or high severity taint flows were detected, the presence of 3 high severity taint flows indicates potential vulnerabilities that could be exploited if certain conditions are met. The vulnerability history is a significant concern, with 4 previously disclosed CVEs, all of medium severity. The common vulnerability types (OS Command Injection, CSRF, PHP Remote File Inclusion) suggest a pattern of weaknesses that have been exploited in the past. Although no currently unpatched vulnerabilities are listed, the historical prevalence of these types of issues warrants caution. The plugin's last reported vulnerability in 2026 suggests the data might be from the future or contain an error, but the historical pattern remains relevant.
Overall, the plugin has made strides in implementing fundamental security controls like authentication and output escaping. The lack of critical or high severity taint flows in the current analysis is encouraging. However, the complete lack of sanitization in all analyzed taint flows, coupled with a history of diverse and serious vulnerability types, presents a notable risk. The plugin requires careful monitoring and prompt patching of any newly discovered vulnerabilities, and a deeper investigation into the nature of the unsanitized paths is recommended.
Key Concerns
- All analyzed taint flows have unsanitized paths
- 3 high severity taint flows detected
- 4 known CVEs (medium severity)
- History of OS Command Injection, CSRF, RFI
Popup Box – Easily Create WordPress Popups Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
Popup Box – Easily Create WordPress Popups <= 3.2.12 - Authenticated (Contributor+) Stored Cross-Site Scripting
Popup Box <= 3.2.4 - Cross-Site Request Forgery
Popup Box – new WordPress popup plugin <= 2.2.6 - Cross-Site Request Forgery
Popup Box <= 2.1.2 - Authenticated Local File Inclusion
Popup Box – Easily Create WordPress Popups Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Popup Box – Easily Create WordPress Popups Attack Surface
AJAX Handlers 1
Shortcodes 3
WordPress Hooks 13
Maintenance & Trust
Popup Box – Easily Create WordPress Popups Maintenance & Trust
Maintenance Signals
Community Trust
Popup Box – Easily Create WordPress Popups Alternatives
MaxedAnnounce — Notification Bar (Top & Bottom)
maxedannounce-notification-bar
Create and manage notification bars with rich customization options. Display customizable bars at the top or bottom of your website.
Modal Window – create popup modal window
modal-window
WordPress popup plugin for easily creating a popup and modal window with any kind of content and settings.
Easy Modal
easy-modal
The #1 WordPress Popup Plugin! Make glorious & powerful popups and market your content like never before - all in minutes!
Popup for CF7 with Sweet Alert
cf7-sweet-alert-popup
Popup for CF7 with Sweet Alert
Disclaimer Popup
disclaimer-popup
Disclaimer Popup is a free plugin that will help you to quickly create a disclaimer popup complete with texts and images
Popup Box – Easily Create WordPress Popups Developer Profile
25 plugins · 98K total installs
How We Detect Popup Box – Easily Create WordPress Popups
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/popup-box/admin/css/style.css/wp-content/plugins/popup-box/public/css/popup-box-style.css/wp-content/plugins/popup-box/public/js/popup-box-script.js/wp-content/plugins/popup-box/public/js/popup-box-script.jspopup-box/admin/css/style.css?ver=popup-box/public/css/popup-box-style.css?ver=popup-box/public/js/popup-box-script.js?ver=HTML / DOM Fingerprints
popup-box-wrappopup-box-closepopup-box-contentpopup-box-wrapperpopup-box-dialogpopup-box-headerpopup-box-bodydata-popupbox-iddata-popupbox-layoutdata-popupbox-widthdata-popupbox-heightdata-popupbox-effectdata-popupbox-position+6 morepopupbox_localize_data[Popup-Box