
Sayonara – Advanced Popup Builder Security & Risk Analysis
wordpress.org/plugins/sayonaraFinally! A popup builder, fully supported, regularly updated, secure, and free. No monthly subscriptions required with external companies.
Is Sayonara – Advanced Popup Builder Safe to Use in 2026?
Generally Safe
Score 85/100Sayonara – Advanced Popup Builder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "sayonara" plugin v1.0.1 exhibits a generally good security posture with no known historical vulnerabilities. Static analysis indicates a very small attack surface, with zero identified entry points for potential exploitation. The code demonstrates strong adherence to security best practices, evidenced by the complete absence of dangerous functions, file operations, and external HTTP requests. Furthermore, all SQL queries are properly prepared, and the presence of nonce and capability checks in the code is encouraging.
However, a notable concern arises from the taint analysis, which identified one flow with an unsanitized path. While this flow did not reach a critical or high severity, it still represents a potential weakness that could be exploited under specific conditions. Additionally, the output escaping is not perfectly implemented, with 67% properly escaped, leaving a portion of outputs potentially vulnerable to cross-site scripting (XSS) if user-supplied data is involved and not sufficiently sanitized elsewhere. The bundled Select2 library, while not inherently a vulnerability, warrants attention as bundled libraries can sometimes become outdated and introduce security risks if not actively maintained.
Given the clean vulnerability history and the limited attack surface, the overall risk is low. The plugin benefits from robust practices like prepared statements and capability checks. However, the identified unsanitized path and partially unescaped outputs represent areas for improvement to further strengthen its security and mitigate potential risks, particularly concerning XSS vulnerabilities.
Key Concerns
- Flow with unsanitized path detected
- Output escaping not fully implemented
Sayonara – Advanced Popup Builder Security Vulnerabilities
Sayonara – Advanced Popup Builder Release Timeline
Sayonara – Advanced Popup Builder Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Sayonara – Advanced Popup Builder Attack Surface
WordPress Hooks 14
Maintenance & Trust
Sayonara – Advanced Popup Builder Maintenance & Trust
Maintenance Signals
Community Trust
Sayonara – Advanced Popup Builder Alternatives
Popup Box – Create Countdown, Coupon, Video, Contact Form Popups
ays-popup-box
Build flexible popups and modal windows with multiple popup types, triggers, and display controls.
Smart Popup by Supsystic
popup-by-supsystic
Create targeted popups for lead capture, event notifications, announcements, and promotions — shown at the right time without disrupting your visitors …
Kicklander
kicklander
Instantly convert & monetize your traffic using our platform to create no-code notifications that call to an action.
Popup Maker and Popup Anything – Popup for opt-ins and Lead Generation Conversions
popup-anything-on-click
Create popup on a page load or Create popup by clicking link, image and button. Create popups, opt-in forms, & exit popups, floating bars and more!
Poptin – Exit Pop Ups & Email Popups
poptin
Free exit intent popup builder, gamified popups with spin the wheel, contact form builder & lead generation pop ups platform for your website. 🎉
Sayonara – Advanced Popup Builder Developer Profile
6 plugins · 2K total installs
How We Detect Sayonara – Advanced Popup Builder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sayonara/admin/css/sayonara-admin.css/wp-content/plugins/sayonara/admin/css/select2.min.css/wp-content/plugins/sayonara/admin/js/sayonara-admin.js/wp-content/plugins/sayonara/admin/js/select2.min.js/wp-content/plugins/sayonara/admin/js/sayonara-admin.js/wp-content/plugins/sayonara/admin/js/select2.min.jssayonara-admin.css?ver=select2.min.css?ver=sayonara-admin.js?ver=select2.min.js?ver=