
Smart Popup by Supsystic Security & Risk Analysis
wordpress.org/plugins/popup-by-supsysticCreate targeted popups for lead capture, event notifications, announcements, and promotions — shown at the right time without disrupting your visitors …
Is Smart Popup by Supsystic Safe to Use in 2026?
Generally Safe
Score 91/100Smart Popup by Supsystic has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The plugin 'popup-by-supsystic' v1.10.38 presents a mixed security posture. While the static analysis indicates a small attack surface with no immediately apparent unprotected entry points, significant concerns arise from the presence of dangerous functions and a substantial history of vulnerabilities. The use of `unserialize` is a notable red flag, as it can lead to Remote Code Execution if not handled with extreme care and proper input sanitization. Furthermore, the fact that 50% of outputs are not properly escaped suggests a potential for Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the website.
The plugin's vulnerability history is particularly concerning, with a total of 8 known CVEs, including 1 critical, 2 high, and 5 medium severity vulnerabilities. The types of past vulnerabilities, such as Improper Neutralization of Special Elements Used in a Template Engine, Missing Authorization, CSRF, Prototype Pollution, Information Exposure, and XSS, indicate a recurring pattern of insecure coding practices. The fact that a critical vulnerability was last patched only recently (though the date seems to be a placeholder in the provided data) does not negate the history of past serious flaws.
In conclusion, despite a seemingly limited attack surface in the current version's static analysis, the plugin's history of critical and high-severity vulnerabilities, coupled with the use of dangerous functions like `unserialize` and a high rate of unescaped output, warrants a cautious approach. The past patterns suggest a need for thorough ongoing security audits and a high level of vigilance when using this plugin.
Key Concerns
- Dangerous function used (unserialize)
- Low percentage of properly escaped output
- Significant history of critical/high CVEs
- History of critical severity vulnerabilities
- History of high severity vulnerabilities
- History of medium severity vulnerabilities
Smart Popup by Supsystic Security Vulnerabilities
CVEs by Year
Severity Breakdown
8 total CVEs
Popup by Supsystic <= 1.10.29 - Authenticated (Admin+) Remote Code Execution
Popup by Supsystic <= 1.10.27 - Missing Authorization
Popup by Supsystic <= 1.10.19 - Missing Authorization to Sensitive Information Exposure
Popup by Supsystic <= 1.10.19 - Cross-Site Request Forgery
Popup by Supsystic <= 1.10.18 - Prototype Pollution
Popup by Supsystic <= 1.10.8 - Sensitive Information Disclosure
Popup by Supsystic <= 1.10.4 - Reflected Cross-Site Scripting
Popup by Supsystic < 1.7.9 - Cross-Site Request Forgery
Smart Popup by Supsystic Release Timeline
Smart Popup by Supsystic Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Smart Popup by Supsystic Attack Surface
Shortcodes 1
WordPress Hooks 48
Maintenance & Trust
Smart Popup by Supsystic Maintenance & Trust
Maintenance Signals
Community Trust
Smart Popup by Supsystic Alternatives
Popup Box – Create Countdown, Coupon, Video, Contact Form Popups
ays-popup-box
Build flexible popups and modal windows with multiple popup types, triggers, and display controls.
Poptin – Exit Pop Ups & Email Popups
poptin
Free exit intent popup builder, gamified popups with spin the wheel, contact form builder & lead generation pop ups platform for your website. 🎉
Pop-up
pop-up-pop-up
Pop-up Popups
Modal Popup Box
modal-popup-box
Create and manage customizable modal popup boxes with CSS animations. Embed images, videos, forms, shortcodes, and more.
Nelio Popups
nelio-popups
An intuitive popup designer based on open WordPress technologies
Smart Popup by Supsystic Developer Profile
7 plugins · 97K total installs
How We Detect Smart Popup by Supsystic
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/popup-by-supsystic/classes/css//wp-content/plugins/popup-by-supsystic/js//wp-content/plugins/popup-by-supsystic/js/popup.jspopup-by-supsystic/classes/css/style.css?ver=popup-by-supsystic/js/popup.js?ver=HTML / DOM Fingerprints
pps-popup-contentpps-popup-overlay<!-- popup-by-supsystic START --><!-- popup-by-supsystic END -->data-pps-iddata-pps-typepps/wp-json/pps/v1/popup/