Popup Maker – BuddyPress Integration Security & Risk Analysis

wordpress.org/plugins/popup-maker-buddypress-integration

Adds integrated functionality between Popup Maker & BuddyPress.

100 active installs v1.0.0 PHP + WP 3.6+ Updated Oct 24, 2018
buddypresspopuppopup-makertargeting
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Popup Maker – BuddyPress Integration Safe to Use in 2026?

Generally Safe

Score 85/100

Popup Maker – BuddyPress Integration has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The static analysis of "popup-maker-buddypress-integration" v1.0.0 reveals a generally strong security posture with no identified attack surface, dangerous functions, file operations, external HTTP requests, or taint flows. This suggests the plugin developers have prioritized secure coding practices in these areas.

However, there are significant concerns regarding SQL query handling and output escaping. The single SQL query is not using prepared statements, which is a critical vulnerability that could lead to SQL injection. Furthermore, only 50% of outputting is properly escaped, indicating a potential for cross-site scripting (XSS) vulnerabilities. The complete absence of nonce checks and capability checks on entry points, although the attack surface is currently zero, leaves the plugin vulnerable if new entry points are introduced without proper authorization.

The plugin's vulnerability history is clean, with no known CVEs. This is a positive sign, but it does not negate the immediate risks identified in the static analysis. The lack of past vulnerabilities might be due to the plugin's limited scope or the absence of attackers specifically targeting it. The current findings, particularly the unescaped output and raw SQL query, warrant immediate attention to prevent exploitation.

Key Concerns

  • SQL query without prepared statements
  • Unescaped output (50% of total)
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Popup Maker – BuddyPress Integration Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Popup Maker – BuddyPress Integration Release Timeline

v1.0.0Current
Code Analysis
Analyzed Mar 16, 2026

Popup Maker – BuddyPress Integration Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
5
5 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

50% escaped10 total outputs
Attack Surface

Popup Maker – BuddyPress Integration Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
filterpum_registered_conditionsclasses\Conditions.php:9
filterpum_condition_sort_orderclasses\Conditions.php:10
actionpum_register_upgradesclasses\Upgrades.php:50
actionadmin_noticesincludes\pum-sdk\class-pum-extension-activator.php:140
filterpum_enabled_extensionsincludes\pum-sdk\class-pum-extension-activator.php:157
filterpum_autoloaderspopup-maker-buddypress-integration.php:36
actionadmin_noticespopup-maker-buddypress-integration.php:142
actionplugins_loadedpopup-maker-buddypress-integration.php:231
Maintenance & Trust

Popup Maker – BuddyPress Integration Maintenance & Trust

Maintenance Signals

WordPress version tested5.0.0
Last updatedOct 24, 2018
PHP min version
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

Popup Maker – BuddyPress Integration Developer Profile

Daniel Iser

8 plugins · 827K total installs

68
trust score
Avg Security Score
84/100
Avg Patch Time
588 days
View full developer profile
Detection Fingerprints

How We Detect Popup Maker – BuddyPress Integration

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/popup-maker-buddypress-integration/

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Popup Maker – BuddyPress Integration