Scroll Popup Ads Security & Risk Analysis

wordpress.org/plugins/scroll-popup

Responsive Scroll PoPup Ads Manager for WordPress.

10 active installs v1.0.2 PHP + WP 4.0.0+ Updated Unknown
advertisementsmodal-windowpopuppopup-ads
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Scroll Popup Ads Safe to Use in 2026?

Generally Safe

Score 100/100

Scroll Popup Ads has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

Based on the provided static analysis and vulnerability history, the 'scroll-popup' plugin v1.0.2 exhibits a generally good security posture. The absence of identified CVEs, dangerous functions, raw SQL queries, file operations, and external HTTP requests are positive indicators. Furthermore, the lack of shortcodes, cron events, and a zero total entry points suggest a limited attack surface. However, a significant concern arises from the 55% rate of improperly escaped output. While not directly identified as a vulnerability in the taint analysis (which had zero flows analyzed), unescaped output is a common vector for Cross-Site Scripting (XSS) attacks, especially if user-supplied data is present in these outputs. The lack of nonce and capability checks on the identified entry points, though the count is zero, also represents a potential area for future oversight if new entry points are introduced. The plugin's history of no recorded vulnerabilities is a strong point, but the current code analysis suggests a need for improvement in output sanitization to maintain this record.

Key Concerns

  • Improperly escaped output identified
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

Scroll Popup Ads Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Scroll Popup Ads Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
37
46 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

55% escaped83 total outputs
Attack Surface

Scroll Popup Ads Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionwp_enqueue_scriptstp-scroll-popup.php:62
actionadmin_enqueue_scriptstp-scroll-popup.php:94
actionwp_headtp-scroll-popup.php:358
actionwp_footertp-scroll-popup.php:383
actionwp_footertp-scroll-popup.php:429
actionadmin_inittp-scroll-popup.php:525
actionadmin_menutp-scroll-popup.php:550
Maintenance & Trust

Scroll Popup Ads Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedUnknown
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Scroll Popup Ads Developer Profile

Themepoints

19 plugins · 10K total installs

84
trust score
Avg Security Score
94/100
Avg Patch Time
66 days
View full developer profile
Detection Fingerprints

How We Detect Scroll Popup Ads

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/scroll-popup/css/animate.css/wp-content/plugins/scroll-popup/css/font-awesome.min.css/wp-content/plugins/scroll-popup/js/jquery.cornerslider.js/wp-content/plugins/scroll-popup/js/admin-media.js/wp-content/plugins/scroll-popup/js/color-picker.js
Script Paths
/wp-content/plugins/scroll-popup/js/jquery.cornerslider.js/wp-content/plugins/scroll-popup/js/admin-media.js/wp-content/plugins/scroll-popup/js/color-picker.js
Version Parameters
scroll-popup/css/animate.css?ver=scroll-popup/css/font-awesome.min.css?ver=scroll-popup/js/jquery.cornerslider.js?ver=scroll-popup/js/admin-media.js?ver=scroll-popup/js/color-picker.js?ver=

HTML / DOM Fingerprints

CSS Classes
spfa-animatespfa-fontawesome
FAQ

Frequently Asked Questions about Scroll Popup Ads