PopX – Popup Builder for Boost Sales, Conversions, Optins, Email Newsletters and Lead Generation Security & Risk Analysis

wordpress.org/plugins/popx-popup-builder

Boost sales & conversions, increase engagement & generate leads Grow your business with popx WordPress popup builder plugin! 🚀

0 active installs v1.0.2 PHP 7.4+ WP 6.5+ Updated Dec 13, 2024
conversiongutenbergmarketingpopuppopup-builder
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is PopX – Popup Builder for Boost Sales, Conversions, Optins, Email Newsletters and Lead Generation Safe to Use in 2026?

Generally Safe

Score 92/100

PopX – Popup Builder for Boost Sales, Conversions, Optins, Email Newsletters and Lead Generation has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The plugin 'popx-popup-builder' version 1.0.2 presents a mixed security posture. On the positive side, the plugin demonstrates good practices regarding SQL query handling, exclusively using prepared statements, and shows a high percentage of properly escaped output, indicating an effort to prevent cross-site scripting vulnerabilities. It also correctly implements nonce and capability checks for some entry points and has no recorded vulnerability history, suggesting a generally stable codebase.

However, significant concerns arise from the attack surface. The presence of two AJAX handlers without authentication checks creates a direct risk. This means that any user, regardless of their logged-in status or role, can potentially trigger these functionalities, which could lead to unauthorized actions or information disclosure if these handlers are not inherently safe. The lack of taint analysis results is also noted, though the absence of critical or high severity flows is a good sign.

In conclusion, while the plugin avoids common pitfalls like raw SQL queries and has a clean vulnerability record, the unprotected AJAX endpoints are a critical weakness that needs immediate attention. The strength in its SQL and output sanitization is commendable, but the exposed entry points overshadow these positives, leading to a moderate overall risk.

Key Concerns

  • AJAX handlers without auth checks
Vulnerabilities
None known

PopX – Popup Builder for Boost Sales, Conversions, Optins, Email Newsletters and Lead Generation Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

PopX – Popup Builder for Boost Sales, Conversions, Optins, Email Newsletters and Lead Generation Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
30
219 escaped
Nonce Checks
4
Capability Checks
4
File Operations
0
External Requests
2
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

88% escaped249 total outputs
Attack Surface
2 unprotected

PopX – Popup Builder for Boost Sales, Conversions, Optins, Email Newsletters and Lead Generation Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_render_popx_popuppopx.php:68
noprivwp_ajax_render_popx_popuppopx.php:69
WordPress Hooks 17
actionswitch_themeappsero\src\Insights.php:140
actionswitch_themeappsero\src\Insights.php:141
actionadmin_footerappsero\src\Insights.php:158
actionadmin_noticesappsero\src\Insights.php:175
actionadmin_initappsero\src\Insights.php:178
filtercron_schedulesappsero\src\Insights.php:184
actionadmin_menuappsero\src\License.php:219
actionafter_switch_themeappsero\src\License.php:781
actionswitch_themeappsero\src\License.php:782
actionadd_meta_boxesclasses\Meta_Base.php:21
actionsave_postclasses\Meta_Base.php:22
actioninitclasses\Post_Type_Base.php:19
actionadmin_enqueue_scriptscore\fields\Fields_Maping.php:32
actionwp_footerinc\WP_Hooks.php:19
actioninitpopx.php:50
filterplugin_action_linkspopx.php:66
filterwp_enqueue_scriptspopx.php:67
Maintenance & Trust

PopX – Popup Builder for Boost Sales, Conversions, Optins, Email Newsletters and Lead Generation Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedDec 13, 2024
PHP min version7.4
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

PopX – Popup Builder for Boost Sales, Conversions, Optins, Email Newsletters and Lead Generation Developer Profile

wpmobo

4 plugins · 60 total installs

93
trust score
Avg Security Score
98/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect PopX – Popup Builder for Boost Sales, Conversions, Optins, Email Newsletters and Lead Generation

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/popx-popup-builder/assets/css/main.css/wp-content/plugins/popx-popup-builder/assets/js/main.js/wp-content/plugins/popx-popup-builder/core/fields/assets/css/jquery-ui.css/wp-content/plugins/popx-popup-builder/core/fields/assets/css/fields.css/wp-content/plugins/popx-popup-builder/core/fields/assets/js/wp-color-picker-alpha.js/wp-content/plugins/popx-popup-builder/core/fields/assets/js/fields.js
Script Paths
/wp-content/plugins/popx-popup-builder/assets/js/main.js
Version Parameters
popx-popup-builderpopx-popup-builder/assets/css/main.css?ver=popx-popup-builder/assets/js/main.js?ver=popx-popup-builder/core/fields/assets/css/jquery-ui.css?ver=popx-popup-builder/core/fields/assets/css/fields.css?ver=popx-popup-builder/core/fields/assets/js/wp-color-picker-alpha.js?ver=popx-popup-builder/core/fields/assets/js/fields.js?ver=

HTML / DOM Fingerprints

CSS Classes
popx-base-wrap
Data Attributes
data-popx-popup-positiondata-popx-active-popupdata-popx-popup-bg-overlydata-popx-popup-delay-timedata-popx-popup-popup-widthdata-popx-popup-popup-height
JS Globals
popxScript
FAQ

Frequently Asked Questions about PopX – Popup Builder for Boost Sales, Conversions, Optins, Email Newsletters and Lead Generation