
Popup in Posts, Pages Security & Risk Analysis
wordpress.org/plugins/popup-in-posts-pagesCreate popups with Tinymce, within posts and pages..
Is Popup in Posts, Pages Safe to Use in 2026?
Generally Safe
Score 85/100Popup in Posts, Pages has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "popup-in-posts-pages" v1.2 appears to have a generally good security posture based on the provided static analysis. It demonstrates adherence to secure coding practices by avoiding dangerous functions, utilizing prepared statements for all SQL queries, and not performing file operations or external HTTP requests. The presence of nonce checks further indicates an effort to prevent common cross-site request forgery attacks.
However, there are notable areas of concern. The plugin exhibits a low percentage of properly escaped output, meaning data displayed to users could potentially be manipulated or lead to cross-site scripting vulnerabilities if user-supplied data is involved and not properly sanitized before output. Furthermore, the lack of capability checks on the identified shortcode entry point is a significant risk, as it could allow unauthenticated users to trigger the shortcode's functionality, potentially leading to unintended consequences or information disclosure.
The vulnerability history shows no known CVEs, which is a positive sign. This, combined with the absence of critical or high severity taint flows, suggests that the plugin has not historically been a significant target for severe security flaws. Despite the strengths in SQL handling and avoiding risky functions, the identified output escaping and capability check deficiencies present tangible risks that warrant attention.
Key Concerns
- Low output escaping percentage
- Shortcode without capability checks
Popup in Posts, Pages Security Vulnerabilities
Popup in Posts, Pages Code Analysis
Output Escaping
Popup in Posts, Pages Attack Surface
Shortcodes 1
WordPress Hooks 10
Maintenance & Trust
Popup in Posts, Pages Maintenance & Trust
Maintenance Signals
Community Trust
Popup in Posts, Pages Alternatives
Related Posts By PickPlugins
related-post
Display Related Post under post by taxonomy and terms.
Inline Related Posts
intelly-related-posts
Inline Related Posts AUTOMATICALLY inserts related posts INSIDE your content, capturing immediately the reader's attention.
Related Posts for WordPress
related-posts-for-wp
The best WordPress plugin for related posts. Simple, flexible, powerful algorithm, and built-in caching. Fully setup with only 1 click!
WP Dummy Content Generator
wp-dummy-content-generator
Generate realistic dummy content for WordPress quickly. Ideal for developers and designers to populate sites for testing and development.
Internal Linking of Related Contents
internal-linking-of-related-contents
Internal Linking of Related Contents allows you to automatically insert inline related posts within your WordPress articles.
Popup in Posts, Pages Developer Profile
4 plugins · 2K total installs
How We Detect Popup in Posts, Pages
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/popup-in-posts-pages/popup_script.php/wp-content/plugins/popup-in-posts-pages/popup_script.phpHTML / DOM Fingerprints
a_pupupihpi_OnePopupBlockpopup_blocktxeachFieldX<!-- ... -->data-namepopupi_contentsshow_my_popup[popupi[/popupi]