
Popup Builder – Create highly converting, mobile friendly marketing popups. Security & Risk Analysis
wordpress.org/plugins/popup-builderIncrease Sales, Lead Generation, Conversion rates and receive good Call to Action rates with smart WordPress popup plugin.
Is Popup Builder – Create highly converting, mobile friendly marketing popups. Safe to Use in 2026?
Mostly Safe
Score 76/100Popup Builder – Create highly converting, mobile friendly marketing popups. is generally safe to use. 23 past CVEs were resolved. Keep it updated.
The "popup-builder" plugin exhibits a mixed security posture. While static analysis indicates a strong adherence to basic security practices, such as 100% output escaping and a high percentage of prepared SQL statements, several areas raise concerns. The presence of 6 flows with unsanitized paths, including 3 of critical severity from the taint analysis, directly points to potential vulnerabilities that could be exploited. The large number of AJAX handlers (33) without authentication checks, although reported as '0 Unprotected' in the summary, warrants closer inspection for proper authorization mechanisms within these handlers.
The plugin's vulnerability history is a significant red flag. With a total of 23 known CVEs, including 3 critical and 6 high-severity issues, this indicates a recurring pattern of security weaknesses. The diverse range of past vulnerability types, from SQL Injection and SSRF to XSS and deserialization issues, suggests a deep-seated need for more robust secure coding practices and thorough code reviews. While there are currently no unpatched CVEs, the sheer volume and historical severity of past vulnerabilities suggest a high likelihood of future discoveries if fundamental coding practices are not improved.
In conclusion, while the plugin has implemented some good security measures, the critical taint analysis findings and the extensive history of severe vulnerabilities cannot be ignored. The plugin is a high risk due to the potential for exploitable code paths and its past security track record. Efforts should focus on addressing the identified unsanitized paths and a comprehensive review of authorization and input validation across all entry points.
Key Concerns
- Critical severity taint flow found
- High severity taint flow found
- Total known CVEs: 23 (indicates recurring vulnerabilities)
- 3 critical CVEs in history
- 6 high CVEs in history
- Flows with unsanitized paths: 6
- Bundled library: Select2 (potential for outdated/vulnerable)
Popup Builder – Create highly converting, mobile friendly marketing popups. Security Vulnerabilities
CVEs by Year
Severity Breakdown
23 total CVEs
Popup Builder - Create highly converting, mobile friendly marketing popups. <= 4.4.2 - Improper Authorization to Unauthenticated Subscriber Removal via Predictable Tokens
Popup Builder – Create highly converting, mobile friendly marketing popups. <= 4.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Popup Builder <= 4.3.4 - Authenticated (Admin+) Stored Cross-Site Scripting
Popup Builder <= 4.3.6 - Sensitive Information Exposure via Imported Subscribers CSV File
Popup Builder <= 4.3.0 - Missing Authorization in Multiple AJAX Actions
Popup Builder – Create highly converting, mobile friendly marketing popups <= 4.3.1 - Missing Authorization and Nonce Exposure
Popup Builder <= 4.2.7 - Authenticated(Contributor+) Stored Cross-Site Scripting via Custom JS
Popup Builder <= 4.2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Popup Builder <= 4.2.5 - Authenticated (Admin+) Server-Side Request Forgery
Popup Builder <= 4.2.2 - Unauthenticated Stored Cross-Site Scripting
Popup Builder <= 4.2.1 - Authenticated (Admin+) Stored Cross-Site Scripting
Popup Builder – Create highly converting, mobile friendly marketing popups. <= 4.1.11 - Cross-Site Request Forgery to Settings Update
Popup Builder <= 4.1.10 - Authenticated (Admin+) Cross-Site Scripting
Popup Builder <= 4.1.0 - Cross-Site Request Forgery
Popup Builder <= 4.1.0 - SQL Injection
Popup Builder <= 4.0.6 - Authenticated SQL Injection via order & orderby Parameters
Popup Builder <= 4.0.6 - Local File Inclusion and PHAR Deserialization
Popup Builder <= 3.73 - Reflected Cross-Site Scripting
Popup Builder <= 3.72 Missing Authorization on AJAX actions
Popup Builder <= 3.63 - Unauthenticated Stored Cross-Site Scripting
Popup Builder <= 3.63 - Authenticated Settings Modification, Configuration Disclosure, and User Data Export
Popup Builder 2.2.8 - 2.6.7.6 - PHP Object Injection
Popup Builder <= 3.44 - SQL Injection
Popup Builder – Create highly converting, mobile friendly marketing popups. Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Popup Builder – Create highly converting, mobile friendly marketing popups. Attack Surface
AJAX Handlers 33
Shortcodes 1
WordPress Hooks 125
Scheduled Events 2
Maintenance & Trust
Popup Builder – Create highly converting, mobile friendly marketing popups. Maintenance & Trust
Maintenance Signals
Community Trust
Popup Builder – Create highly converting, mobile friendly marketing popups. Alternatives
Modal Popup Box: A Flexible Pop Up Box Builder
modal-popup-box
Create and manage a customizable pop up box on your WordPress website. Embed anything from videos and images to forms and shortcodes.
Claspo – Popups, Spin the Wheel & Email Capture
claspo
Grow your email list and increase sales! Use the Claspo Popup Maker plugin to create pop-up windows, Spin the Wheel, Exit Intent, and Lead Gen forms.
Popup – Popup Maker
popup-wp
Popup - Popup Maker makes it a breeze to convert visitors into leads, subscribers, and sales! Convert leads into customers.
CS Popup Maker
cs-popup-maker
A simple plugin to show popup image in homepage or any other pages which is controlled from WordPress admin panel.
Popup Builder & Opt-in Forms – Exit Intent, Coupon & Floating Bar Popups by YSLeadGen
ysleadgen
Popup builder for exit intent popups, coupon popups, floating bars, and opt-in forms to grow leads and increase conversions on WordPress sites.
Popup Builder – Create highly converting, mobile friendly marketing popups. Developer Profile
3 plugins · 201K total installs
How We Detect Popup Builder – Create highly converting, mobile friendly marketing popups.
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/popup-builder/css/sgpb-style.css/wp-content/plugins/popup-builder/css/sgpb-admin-style.css/wp-content/plugins/popup-builder/js/sgpb-admin-script.js/wp-content/plugins/popup-builder/js/sgpb-popup-script.js/wp-content/plugins/popup-builder/js/sgpb-settings-script.js/wp-content/plugins/popup-builder/js/sgpb-preview-script.js/wp-content/plugins/popup-builder/js/sgpb-addons-script.js/wp-content/plugins/popup-builder/js/sgpb-categories-script.js+5 more/wp-content/plugins/popup-builder/js/sgpb-admin-script.js/wp-content/plugins/popup-builder/js/sgpb-popup-script.js/wp-content/plugins/popup-builder/js/sgpb-settings-script.js/wp-content/plugins/popup-builder/js/sgpb-preview-script.js/wp-content/plugins/popup-builder/js/sgpb-addons-script.js/wp-content/plugins/popup-builder/js/sgpb-categories-script.js+5 morepopup-builder/css/sgpb-style.css?ver=popup-builder/css/sgpb-admin-style.css?ver=popup-builder/js/sgpb-admin-script.js?ver=popup-builder/js/sgpb-popup-script.js?ver=popup-builder/js/sgpb-settings-script.js?ver=popup-builder/js/sgpb-preview-script.js?ver=popup-builder/js/sgpb-addons-script.js?ver=popup-builder/js/sgpb-categories-script.js?ver=popup-builder/js/sgpb-effects-script.js?ver=popup-builder/js/sgpb-custom-popup-type.js?ver=popup-builder/js/sgpb-templates-script.js?ver=popup-builder/js/sgpb-reports-script.js?ver=popup-builder/js/sgpb-feedback-script.js?ver=HTML / DOM Fingerprints
sgpb-tablesgpb-table-wrapsgpb-admin-wrapper<!-- SLIDER -->data-sgpb-iddata-sgpb-typedata-sgpb-delaydata-sgpb-popup-iddata-sgpb-hide-on-mobiledata-sgpb-show-on-mobile+2 moreSGPB_POPUP_VERSIONsgpbBackendSGPBAdminParams/wp-json/sgpb/v1/popups[sg_popup