
Popup Maker – Responsive popup, Exit Intent Pop up, Email Optins, Autoresponder & More Security & Risk Analysis
wordpress.org/plugins/popup-maker-wpPopup Maker plugin will help you run cleverer and more effective marketing popups for your website. Create the most optimal popup to boost your sales.
Is Popup Maker – Responsive popup, Exit Intent Pop up, Email Optins, Autoresponder & More Safe to Use in 2026?
Generally Safe
Score 99/100Popup Maker – Responsive popup, Exit Intent Pop up, Email Optins, Autoresponder & More has a strong security track record. Known vulnerabilities have been patched promptly.
The "popup-maker-wp" plugin v1.4.4 exhibits a mixed security posture. On the positive side, the plugin demonstrates strong adherence to secure coding practices by utilizing prepared statements for all SQL queries and ensuring a high percentage of output is properly escaped. The absence of critical or high-severity taint flows, raw SQL queries, and file operations are also positive indicators. The plugin's vulnerability history, while showing one past medium vulnerability, currently has no unpatched CVEs, which is a good sign of maintenance.
However, the plugin presents a significant concern regarding its attack surface. With 7 AJAX handlers, 5 of which lack authentication checks, there is a substantial risk of unauthorized access or manipulation of plugin functionalities. While the static analysis did not reveal specific dangerous functions or unsanitized paths in taint flows, the unprotected AJAX endpoints represent a potential entry point for various attacks if further vulnerabilities exist within those handlers. The presence of bundled libraries like Select2 also warrants attention, as outdated versions of such libraries can introduce vulnerabilities, though no specific information on the version's security is provided.
In conclusion, while the plugin has a foundation of good security practices, the large number of unprotected AJAX endpoints is a critical weakness that exposes it to significant risk. Prompt attention to securing these entry points is essential to mitigate potential threats. The absence of current unpatched vulnerabilities and the general adherence to secure coding practices for SQL and output escaping are strengths, but they are overshadowed by the identified attack surface vulnerabilities.
Key Concerns
- Large attack surface without auth (AJAX)
- Bundled libraries (Select2)
Popup Maker – Responsive popup, Exit Intent Pop up, Email Optins, Autoresponder & More Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Popup Maker – Responsive popup, Exit Intent Pop up, Email Optins, Autoresponder & More <= 1.3.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting
Popup Maker – Responsive popup, Exit Intent Pop up, Email Optins, Autoresponder & More Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Popup Maker – Responsive popup, Exit Intent Pop up, Email Optins, Autoresponder & More Attack Surface
AJAX Handlers 7
WordPress Hooks 21
Maintenance & Trust
Popup Maker – Responsive popup, Exit Intent Pop up, Email Optins, Autoresponder & More Maintenance & Trust
Maintenance Signals
Community Trust
Popup Maker – Responsive popup, Exit Intent Pop up, Email Optins, Autoresponder & More Alternatives
Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers
popup-builder-block
Powerful Popup Builder Block for Gutenberg block editor.
Exit Popup
exit-popup
Display a jQuery modal window, which can include text, images, videos, forms, maps and so on, before a visitor leaves your website.
Yeloni Exit Popup | (Free) GDPR Compliance
yeloni-free-exit-popup
Powerful lead generation plugin that converts abandoning visitors into subscribers using exit intent, page level targeting & custom designs.
Popup – Popup Maker
popup-wp
Popup - Popup Maker makes it a breeze to convert visitors into leads, subscribers, and sales! Convert leads into customers.
Advanced Exit Popup
advanced-exit-popup
Advanced Exit Popup allows you to display custom code like HTML5, Subscription forms, Shortcodes, etc when user intent to exit your website on desktop …
Popup Maker – Responsive popup, Exit Intent Pop up, Email Optins, Autoresponder & More Developer Profile
1 plugin · 7K total installs
How We Detect Popup Maker – Responsive popup, Exit Intent Pop up, Email Optins, Autoresponder & More
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/popup-maker-wp/assets/css/admin.css/wp-content/plugins/popup-maker-wp/assets/css/notification-shade.csspopup-maker-wp/assets/css/admin.css?ver=popup-maker-wp/assets/css/notification-shade.css?ver=HTML / DOM Fingerprints
sgpm-notification-shadesgpm-notification-badgedata-sgpm-iddata-notification-typedata-notification-idsgpm_clear_all_notificationssgpm_remove_notificationSGPMBasePlugin_Usage_Tracker