
POPUP Zyrex Security & Risk Analysis
wordpress.org/plugins/popup-zyrexLightweight popup/banner plugin with multiple triggers, positions, targeting, analytics — translated into 6 languages.
Is POPUP Zyrex Safe to Use in 2026?
Generally Safe
Score 99/100POPUP Zyrex has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "popup-zyrex" v1.2.2 plugin exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices in SQL query handling and output escaping, with a high percentage of queries using prepared statements and outputs being properly escaped. It also avoids external HTTP requests and has no known bundled libraries that could introduce vulnerabilities. However, there are significant areas of concern that warrant attention.
The static analysis reveals a critical weakness in its taint analysis. Two flows with unsanitized paths were identified, indicating potential for attackers to manipulate data or code execution. While these are not classified as critical severity, the presence of such flows without clear mitigation is a risk. Furthermore, the complete absence of nonce checks and capability checks across all identified entry points (though the attack surface is reported as zero) is a glaring security oversight. This suggests that if any entry points were to be discovered or introduced, they would likely be unprotected.
The vulnerability history shows a past high-severity vulnerability (Unrestricted Upload of File with Dangerous Type) in April 2023. While currently unpatched CVEs are zero, this past incident highlights a potential recurring pattern of vulnerabilities related to file handling or input validation. The combination of past high-severity issues and the current taint analysis findings suggests a need for more robust input validation and security checks within the plugin's codebase.
Key Concerns
- High severity taint flows found
- Missing nonce checks
- Missing capability checks
- Past high severity vulnerability
- Unsanitized paths in taint flows
POPUP Zyrex Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Zyrex Popup <= 1.0 - Authenticated (Admin+) Arbitrary File Upload
POPUP Zyrex Release Timeline
POPUP Zyrex Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
POPUP Zyrex Attack Surface
WordPress Hooks 4
Maintenance & Trust
POPUP Zyrex Maintenance & Trust
Maintenance Signals
Community Trust
POPUP Zyrex Alternatives
Pop Convert – Free Popup & Smart Bar Plugin for WordPress & WooCommerce
pop-convert
Increase your subscribers list by showing high converting pop ups, banners and smart bars. Collect more emails and phone numbers for retargetting, and …
Popup Box – Create Countdown, Coupon, Video, Contact Form Popups
ays-popup-box
Build flexible popups and modal windows with multiple popup types, triggers, and display controls.
Pop-up
pop-up-pop-up
Pop-up Popups
Smart Popup by Supsystic
popup-by-supsystic
Create targeted popups for lead capture, event notifications, announcements, and promotions — shown at the right time without disrupting your visitors …
Popup Box – Easily Create WordPress Popups
popup-box
Popup Box lets you create responsive, customizable WordPress popups with live preview, flexible triggers, and smart targeting to boost engagement and …
POPUP Zyrex Developer Profile
2 plugins · 10 total installs
How We Detect POPUP Zyrex
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/popup-zyrex/css/main.css/wp-content/plugins/popup-zyrex/js/main.js/wp-includes/js/jquery/jquery.jspopup-zyrex/css/main.css?ver=popup-zyrex/js/main.js?ver=HTML / DOM Fingerprints
popuppopup-hidepopup-contentcloseimg-popupid="js-cookie-popup"id="js-cookie-popup-button"getCookiesetCookieclosePopupScreenopenPopupclosePopup