Sayonara – Advanced Popup Builder Security & Risk Analysis

wordpress.org/plugins/sayonara

Finally! A popup builder, fully supported, regularly updated, secure, and free. No monthly subscriptions required with external companies.

0 active installs v1.0.1 PHP 5.6+ WP 3.0.1+ Updated Jul 3, 2020
exit-popupintentmodalpopuppopups
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Sayonara – Advanced Popup Builder Safe to Use in 2026?

Generally Safe

Score 85/100

Sayonara – Advanced Popup Builder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "sayonara" plugin v1.0.1 exhibits a generally good security posture with no known historical vulnerabilities. Static analysis indicates a very small attack surface, with zero identified entry points for potential exploitation. The code demonstrates strong adherence to security best practices, evidenced by the complete absence of dangerous functions, file operations, and external HTTP requests. Furthermore, all SQL queries are properly prepared, and the presence of nonce and capability checks in the code is encouraging.

However, a notable concern arises from the taint analysis, which identified one flow with an unsanitized path. While this flow did not reach a critical or high severity, it still represents a potential weakness that could be exploited under specific conditions. Additionally, the output escaping is not perfectly implemented, with 67% properly escaped, leaving a portion of outputs potentially vulnerable to cross-site scripting (XSS) if user-supplied data is involved and not sufficiently sanitized elsewhere. The bundled Select2 library, while not inherently a vulnerability, warrants attention as bundled libraries can sometimes become outdated and introduce security risks if not actively maintained.

Given the clean vulnerability history and the limited attack surface, the overall risk is low. The plugin benefits from robust practices like prepared statements and capability checks. However, the identified unsanitized path and partially unescaped outputs represent areas for improvement to further strengthen its security and mitigate potential risks, particularly concerning XSS vulnerabilities.

Key Concerns

  • Flow with unsanitized path detected
  • Output escaping not fully implemented
Vulnerabilities
None known

Sayonara – Advanced Popup Builder Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Sayonara – Advanced Popup Builder Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Sayonara – Advanced Popup Builder Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
24
49 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

67% escaped73 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
render_metabox (admin/class-sayonara-admin.php:260)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Sayonara – Advanced Popup Builder Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 14
filterredirect_post_locationadmin/class-sayonara-admin.php:101
actionmanage_posts_extra_tablenavincludes/class-sayonara-blank-slate.php:59
actionadmin_headincludes/class-sayonara-blank-slate.php:62
actioninitincludes/class-sayonara-cpt.php:29
actionadmin_enqueue_scriptsincludes/class-sayonara.php:147
actionadmin_enqueue_scriptsincludes/class-sayonara.php:148
actioncurrent_screenincludes/class-sayonara.php:149
actionadd_meta_boxesincludes/class-sayonara.php:150
actionsave_post_sayonaraincludes/class-sayonara.php:151
filteradmin_footer_textincludes/class-sayonara.php:152
actionwp_enqueue_scriptsincludes/class-sayonara.php:167
actionwp_enqueue_scriptsincludes/class-sayonara.php:168
actionwp_footerincludes/class-sayonara.php:169
actionfm_post_postsayonara.php:46
Maintenance & Trust

Sayonara – Advanced Popup Builder Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedJul 3, 2020
PHP min version5.6
Downloads942

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Sayonara – Advanced Popup Builder Developer Profile

Ben Roberts

6 plugins · 2K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
1793 days
View full developer profile
Detection Fingerprints

How We Detect Sayonara – Advanced Popup Builder

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sayonara/admin/css/sayonara-admin.css/wp-content/plugins/sayonara/admin/css/select2.min.css/wp-content/plugins/sayonara/admin/js/sayonara-admin.js/wp-content/plugins/sayonara/admin/js/select2.min.js
Script Paths
/wp-content/plugins/sayonara/admin/js/sayonara-admin.js/wp-content/plugins/sayonara/admin/js/select2.min.js
Version Parameters
sayonara-admin.css?ver=select2.min.css?ver=sayonara-admin.js?ver=select2.min.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Sayonara – Advanced Popup Builder