ProProfs Picreel – Popup Builder for Lead Capture & Conversion Security & Risk Analysis

wordpress.org/plugins/proprofs-picreel

Convert visitors into leads with smart popups, precise targeting, and 700+ integrations — all without coding.

0 active installs v1.1.4 PHP 7.0+ WP 4.5+ Updated Dec 3, 2025
exit-intentlead-capturemarketing-automationpicreelpopup-builder
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ProProfs Picreel – Popup Builder for Lead Capture & Conversion Safe to Use in 2026?

Generally Safe

Score 100/100

ProProfs Picreel – Popup Builder for Lead Capture & Conversion has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The proprofs-picreel plugin version 1.1.4 demonstrates a strong security posture based on the static analysis. The absence of dangerous functions, raw SQL queries, and external HTTP requests is commendable. Furthermore, all identified output operations are properly escaped, and file operations are not utilized, significantly reducing the risk of common vulnerabilities. The presence of a nonce check on its single AJAX handler is a positive indicator of security awareness. The plugin also has a clean vulnerability history with no recorded CVEs, suggesting it has been maintained with security in mind.

Despite the generally good security practices, there are a few areas for improvement. The plugin lacks capability checks on its sole entry point (the AJAX handler), which means any authenticated user, regardless of their role, could potentially trigger its functionality. While the current attack surface is small and the taint analysis revealed no issues, this absence of capability checks broadens the potential impact if a vulnerability were to be discovered in the future. The plugin's clean history is a strength, but it does not guarantee future safety, and the lack of capability checks remains a point of concern.

Key Concerns

  • AJAX handler without capability checks
Vulnerabilities
None known

ProProfs Picreel – Popup Builder for Lead Capture & Conversion Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

ProProfs Picreel – Popup Builder for Lead Capture & Conversion Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
10 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped10 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
proprofs_picreel_login_handler (proprofs_picreel.php:45)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

ProProfs Picreel – Popup Builder for Lead Capture & Conversion Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_proprofs_picreel_loginproprofs_picreel.php:44
WordPress Hooks 3
actionadmin_menuproprofs_picreel.php:16
actionadmin_enqueue_scriptsproprofs_picreel.php:64
actionwp_footerproprofs_picreel.php:96
Maintenance & Trust

ProProfs Picreel – Popup Builder for Lead Capture & Conversion Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedDec 3, 2025
PHP min version7.0
Downloads442

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

ProProfs Picreel – Popup Builder for Lead Capture & Conversion Developer Profile

ProProfs

3 plugins · 300 total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ProProfs Picreel – Popup Builder for Lead Capture & Conversion

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/proprofs-picreel/css/dashboard.css/wp-content/plugins/proprofs-picreel/js/dashboard.js/wp-content/plugins/proprofs-picreel/css/login.css/wp-content/plugins/proprofs-picreel/js/login-validation.js
Script Paths
https://app.picreel.com/assets/main.js

HTML / DOM Fingerprints

CSS Classes
picreel_logowelcome-titlerocket-emojisuccess-badgesubtitlelaunch-buttonfeatures-sectionfeatures-title+7 more
HTML Comments
<!-- ProProfs Picreel Script -->
Data Attributes
data-picreeldata-user-email
JS Globals
picreelDashboardDataPicreelAjax
FAQ

Frequently Asked Questions about ProProfs Picreel – Popup Builder for Lead Capture & Conversion