Search Popup ThunderBolt Security & Risk Analysis

wordpress.org/plugins/popup-tb

Search Popup ThunderBolt (Optimate search realtime)

40 active installs v1.1.6 PHP 5.8+ WP + Updated Feb 27, 2024
popuptbsearch
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Search Popup ThunderBolt Safe to Use in 2026?

Generally Safe

Score 85/100

Search Popup ThunderBolt has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "popup-tb" plugin version 1.1.6 exhibits a mixed security posture. While it demonstrates good practices by having no known CVEs, zero taint flows, and utilizing prepared statements for its SQL queries, several areas raise significant concerns. The complete lack of output escaping on all 16 identified output points is a critical weakness, making it highly susceptible to Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the plugin has 10 file operations, which, combined with the unescaped output, could lead to various injection attacks or unauthorized file modifications if an attacker can control the input used in these operations. The plugin's vulnerability history is clean, which is positive, but it doesn't mitigate the inherent risks identified in the static analysis, particularly the unescaped output. Overall, the plugin has strengths in its lack of known historical vulnerabilities and secure SQL handling, but the widespread lack of output escaping presents a substantial and immediate risk.

Key Concerns

  • Unescaped output on all identified points
  • Multiple file operations without clear sanitization
Vulnerabilities
None known

Search Popup ThunderBolt Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Search Popup ThunderBolt Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

Search Popup ThunderBolt Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
16
0 escaped
Nonce Checks
2
Capability Checks
1
File Operations
10
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped16 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
popuptb_json_file_callback (inc\popuptb-content.php:200)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Search Popup ThunderBolt Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_popuptb_json_fileinc\popuptb-content.php:235
authwp_ajax_popuptb_json_folderinc\popuptb-content.php:255
WordPress Hooks 9
actionadmin_menuinc\popuptb-admin.php:176
actionadmin_initinc\popuptb-admin.php:181
actiondelete_postinc\popuptb-content.php:23
actionwp_footerinc\popuptb-content.php:434
actionwp_enqueue_scriptsinc\popuptb-content.php:440
actionwp_enqueue_scriptspopup-tb.php:22
actionplugins_loadedpopup-tb.php:35
actionadmin_headpopup-tb.php:41
filterplugin_action_linkspopup-tb.php:55
Maintenance & Trust

Search Popup ThunderBolt Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedFeb 27, 2024
PHP min version5.8
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs40
Developer Profile

Search Popup ThunderBolt Developer Profile

Fox Plugin

6 plugins · 170 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Search Popup ThunderBolt

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/popup-tb/css/index.css
Version Parameters
popup-tb/css/index.css?ver=

HTML / DOM Fingerprints

Data Attributes
data-popuptb-id
JS Globals
popuptb_options
FAQ

Frequently Asked Questions about Search Popup ThunderBolt