
Promolayer – Popup Builder & Abandonment Preventer Security & Risk Analysis
wordpress.org/plugins/promolayer-popup-builderNot your average popup builder! Boost conversions and subscriptions with beautiful popups, banners, slide-ins, coupon wheels, spin to wins and more.
Is Promolayer – Popup Builder & Abandonment Preventer Safe to Use in 2026?
Generally Safe
Score 99/100Promolayer – Popup Builder & Abandonment Preventer has a strong security track record. Known vulnerabilities have been patched promptly.
The Promolayer Popup Builder plugin v1.1.2 exhibits a mixed security posture, with some strong practices but notable areas of concern. The plugin demonstrates good practices in SQL query handling, exclusively using prepared statements, and a high percentage of output escaping. It also implements nonce checks for its AJAX handlers and has a single capability check, which are positive signs for input validation and authorization. However, the presence of three AJAX handlers without authentication checks creates a significant attack surface. The absence of taint analysis results is a weakness, as it leaves potential vulnerabilities related to data flow and unsanitized inputs unassessed.
The vulnerability history indicates a past issue with 'Missing Authorization', which aligns with the static analysis findings of unprotected AJAX endpoints. While there are no currently unpatched CVEs, the recurring pattern of authorization issues suggests a need for more robust access control mechanisms. The plugin's strengths lie in its data handling and output escaping, but the unprotected entry points represent a clear and present risk that could be exploited for unauthorized actions or data manipulation.
Key Concerns
- AJAX handlers without auth checks
- Missing capability checks on AJAX
- Past vulnerability: Missing Authorization
Promolayer – Popup Builder & Abandonment Preventer Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Pop ups, Exit intent popups, email popups, banners, bars, countdowns and cart savers – Promolayer <= 1.1.0 - Missing Authorization
Promolayer – Popup Builder & Abandonment Preventer Code Analysis
Output Escaping
Promolayer – Popup Builder & Abandonment Preventer Attack Surface
AJAX Handlers 3
WordPress Hooks 15
Maintenance & Trust
Promolayer – Popup Builder & Abandonment Preventer Maintenance & Trust
Maintenance Signals
Community Trust
Promolayer – Popup Builder & Abandonment Preventer Alternatives
Poptics – Popup Builder, Email Opt-ins, Exit-Intent & WooCommerce Popups Sales
poptics
Create high-converting popups, email opt-ins, exit-intent popups & WooCommerce popups to boost leads, subscribers and sales.
Claspo – Popups, Spin the Wheel & Email Capture
claspo
Grow your email list and increase sales! Use the Claspo Popup Maker plugin to create pop-up windows, Spin the Wheel, Exit Intent, and Lead Gen forms.
CocoPopup – Gutenberg Popup Builder for WordPress
cocopopup
Create powerful popups in WordPress with CocoPopup – a flexible Gutenberg popup builder for marketing, WooCommerce & more.
Popup with exit intent, scroll triggered and anchor click for opt-ins, lead gen & more
popper
A popup builder to increase Sales, Lead Generation, Conversion rates and receive good Call to Action with exit intent.
Flash Popup Builder
flash-popup-builder
Flash Popup Builder : A simple popup builder plugin with pre-built templates.
Promolayer – Popup Builder & Abandonment Preventer Developer Profile
1 plugin · 1K total installs
How We Detect Promolayer – Popup Builder & Abandonment Preventer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/promolayer-popup-builder/css/promolayer-admin.css/wp-content/plugins/promolayer-popup-builder/js/promolayer-admin.jshttps://modules.promolayer.io/index.jspromolayer-popup-builder/css/promolayer-admin.css?ver=promolayer-admin.js?ver=HTML / DOM Fingerprints
promolayerdata-promolayer-idpromolayer_admin_params