
Quick Box – Onclick Popup Notification Box Security & Risk Analysis
wordpress.org/plugins/quick-box-popupCreate a javascript based, light-weight and non-annoying onclick popup box in your blog.
Is Quick Box – Onclick Popup Notification Box Safe to Use in 2026?
Generally Safe
Score 85/100Quick Box – Onclick Popup Notification Box has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "quick-box-popup" plugin version 1.2.2 presents a mixed security posture. On the positive side, the plugin has no recorded vulnerabilities (CVEs) and no critical or high severity taint flows were identified, suggesting a generally stable code base and a good track record regarding publicly disclosed security issues. The presence of nonce checks for all identified entry points is also a positive security practice.
However, several areas of concern are evident from the static analysis. The plugin exposes three AJAX handlers, two of which lack authentication checks. This is a significant risk as it could allow unauthenticated users to trigger plugin functionalities, potentially leading to unintended behavior or information disclosure. Furthermore, the plugin uses raw SQL queries without prepared statements, indicating a risk of SQL injection vulnerabilities, especially if user input is incorporated into these queries. The low percentage of properly escaped output (13%) is another major concern, as it points to a high likelihood of cross-site scripting (XSS) vulnerabilities.
While the absence of known vulnerabilities is reassuring, the identified weaknesses in AJAX handler authentication, SQL query sanitization, and output escaping create potential attack vectors. The plugin's strengths lie in its lack of past vulnerabilities and its use of nonces. The key weaknesses are the unprotected AJAX endpoints and poor output escaping, which should be prioritized for remediation.
Key Concerns
- Unprotected AJAX handlers
- SQL queries without prepared statements
- Low percentage of properly escaped output
- Small attack surface without auth
Quick Box – Onclick Popup Notification Box Security Vulnerabilities
Quick Box – Onclick Popup Notification Box Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Quick Box – Onclick Popup Notification Box Attack Surface
AJAX Handlers 3
Shortcodes 2
WordPress Hooks 13
Maintenance & Trust
Quick Box – Onclick Popup Notification Box Maintenance & Trust
Maintenance Signals
Community Trust
Quick Box – Onclick Popup Notification Box Alternatives
No alternatives data available yet.
Quick Box – Onclick Popup Notification Box Developer Profile
15 plugins · 142K total installs
How We Detect Quick Box – Onclick Popup Notification Box
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/quick-box-popup/css/style.css/wp-content/plugins/quick-box-popup/js/notice.js/wp-content/plugins/quick-box-popup/js/qbx_request.jsquick-box-popup/style.css?ver=quick-box-popup/js/notice.js?ver=HTML / DOM Fingerprints
xyz_qbx_containerxyz_qbx_ajax_objectxyz_qbx_ajax_object/wp-json/xyz_qbx_action<span id='xyz_qbx_container'></span>