
PopX – Popup Builder for Boost Sales, Conversions, Optins, Email Newsletters and Lead Generation Security & Risk Analysis
wordpress.org/plugins/popx-popup-builderBoost sales & conversions, increase engagement & generate leads Grow your business with popx WordPress popup builder plugin! 🚀
Is PopX – Popup Builder for Boost Sales, Conversions, Optins, Email Newsletters and Lead Generation Safe to Use in 2026?
Generally Safe
Score 92/100PopX – Popup Builder for Boost Sales, Conversions, Optins, Email Newsletters and Lead Generation has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'popx-popup-builder' version 1.0.2 presents a mixed security posture. On the positive side, the plugin demonstrates good practices regarding SQL query handling, exclusively using prepared statements, and shows a high percentage of properly escaped output, indicating an effort to prevent cross-site scripting vulnerabilities. It also correctly implements nonce and capability checks for some entry points and has no recorded vulnerability history, suggesting a generally stable codebase.
However, significant concerns arise from the attack surface. The presence of two AJAX handlers without authentication checks creates a direct risk. This means that any user, regardless of their logged-in status or role, can potentially trigger these functionalities, which could lead to unauthorized actions or information disclosure if these handlers are not inherently safe. The lack of taint analysis results is also noted, though the absence of critical or high severity flows is a good sign.
In conclusion, while the plugin avoids common pitfalls like raw SQL queries and has a clean vulnerability record, the unprotected AJAX endpoints are a critical weakness that needs immediate attention. The strength in its SQL and output sanitization is commendable, but the exposed entry points overshadow these positives, leading to a moderate overall risk.
Key Concerns
- AJAX handlers without auth checks
PopX – Popup Builder for Boost Sales, Conversions, Optins, Email Newsletters and Lead Generation Security Vulnerabilities
PopX – Popup Builder for Boost Sales, Conversions, Optins, Email Newsletters and Lead Generation Code Analysis
SQL Query Safety
Output Escaping
PopX – Popup Builder for Boost Sales, Conversions, Optins, Email Newsletters and Lead Generation Attack Surface
AJAX Handlers 2
WordPress Hooks 17
Maintenance & Trust
PopX – Popup Builder for Boost Sales, Conversions, Optins, Email Newsletters and Lead Generation Maintenance & Trust
Maintenance Signals
Community Trust
PopX – Popup Builder for Boost Sales, Conversions, Optins, Email Newsletters and Lead Generation Alternatives
Hello Bar Popup Builder: Design Engaging Popups on WordPress
hellobar
Easily add a Popup to your WordPress site with the official HelloBar WordPress plugin.
Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder
popup-maker
Want to boost sales & marketing efforts? Use your favorite forms & builder. Unlimited popups & impressions, keep your data, no monthly subscription.
AI Popup Builder & Popup Maker by OptiMonk
exit-intent-popups-by-optimonk
💥 Popups, supercharged: One platform. Hundreds of use cases. Increase sales & subscribers with popups visitors actually 🧡 love.
Getsitecontrol — Email Marketing Plugin | Popup Maker, Automations & Newsletters
getsitecontrol
Complete email marketing toolset with a powerful popup builder on board. Generate leads with email opt-in forms, send professional newsletters, build …
Floating Awesome Button (Sticky Button, Popup, Toast) & 200+ Website Custom Interactive Element
floating-awesome-button
Floating Awesome Button (FAB) helps website owner, getting more conversion, by adding interactive element such as (Sticky Button, Popup, Toast, etc)
PopX – Popup Builder for Boost Sales, Conversions, Optins, Email Newsletters and Lead Generation Developer Profile
4 plugins · 60 total installs
How We Detect PopX – Popup Builder for Boost Sales, Conversions, Optins, Email Newsletters and Lead Generation
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/popx-popup-builder/assets/css/main.css/wp-content/plugins/popx-popup-builder/assets/js/main.js/wp-content/plugins/popx-popup-builder/core/fields/assets/css/jquery-ui.css/wp-content/plugins/popx-popup-builder/core/fields/assets/css/fields.css/wp-content/plugins/popx-popup-builder/core/fields/assets/js/wp-color-picker-alpha.js/wp-content/plugins/popx-popup-builder/core/fields/assets/js/fields.js/wp-content/plugins/popx-popup-builder/assets/js/main.jspopx-popup-builderpopx-popup-builder/assets/css/main.css?ver=popx-popup-builder/assets/js/main.js?ver=popx-popup-builder/core/fields/assets/css/jquery-ui.css?ver=popx-popup-builder/core/fields/assets/css/fields.css?ver=popx-popup-builder/core/fields/assets/js/wp-color-picker-alpha.js?ver=popx-popup-builder/core/fields/assets/js/fields.js?ver=HTML / DOM Fingerprints
popx-base-wrapdata-popx-popup-positiondata-popx-active-popupdata-popx-popup-bg-overlydata-popx-popup-delay-timedata-popx-popup-popup-widthdata-popx-popup-popup-heightpopxScript