
Popup Message Security & Risk Analysis
wordpress.org/plugins/popup-messageA wordpress plugin which is simply allow you to Display popup flash message after login.
Is Popup Message Safe to Use in 2026?
Generally Safe
Score 85/100Popup Message has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "popup-message" plugin version 0.1 exhibits a mixed security posture. On the positive side, the static analysis reveals no dangerous functions, no direct SQL queries (all use prepared statements), and no file operations or external HTTP requests. Furthermore, the vulnerability history is clean, with no known CVEs associated with this plugin, suggesting a generally stable development history. However, significant concerns arise from the complete lack of output escaping. With 4 total outputs and 0% properly escaped, this presents a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-provided data displayed by the plugin is susceptible to injection. Additionally, the absence of nonce checks and capability checks, coupled with zero AJAX handlers and REST API routes, indicates a lack of robust input validation and authorization mechanisms for potential future entry points, even though the current attack surface is minimal. While the plugin currently has a small attack surface and a clean history, the critical flaw in output escaping creates a significant security risk that outweighs these positive aspects.
Key Concerns
- Outputs not properly escaped (potential XSS)
- Missing nonce checks
- Missing capability checks
Popup Message Security Vulnerabilities
Popup Message Release Timeline
Popup Message Code Analysis
Output Escaping
Popup Message Attack Surface
WordPress Hooks 7
Maintenance & Trust
Popup Message Maintenance & Trust
Maintenance Signals
Community Trust
Popup Message Alternatives
ITRO Popup Plugin
itro-popup
Display a popup to your WordPress site: age verification popup for adult-content site ★ multilanguage popup with qTransalte-X ★ very easy to use
Popups – Submission Messages For Contact Form 7
cf7-popups
Display contact form 7 default messages in stylish popup as user submits the form.
Popup Message Notifier for Contact Form 7
popup-notifier-for-contact-form-7
This plugin will show confirmation and error messages of CF7 inside a popup made with sweetalert2.
Success Fail Popup Message For Contact Form 7
success-fail-popup-message-for-contact-form-7
Success Fail Popup Message For Contact Form 7 to make the best way to set up poup on success and failed messages so a visitor will be attracted to tha …
Smartarget Popup
smartarget-popup
Add Popup window on your website
Popup Message Developer Profile
3 plugins · 30 total installs
How We Detect Popup Message
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/popup-message/assets/style.cssHTML / DOM Fingerprints
ac-popup-messagedashicons-dismissdata-dismissjQuery