
Shortcode Popup Forms Security & Risk Analysis
wordpress.org/plugins/shortcode-popup-formsA lightweight plugin to create a clean, targeted contact form for a specific person using a simple shortcode. Ideal for quick, precise communication.
Is Shortcode Popup Forms Safe to Use in 2026?
Generally Safe
Score 100/100Shortcode Popup Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'shortcode-popup-forms' v1.2.2 demonstrates a strong security posture based on the provided static analysis. It effectively utilizes prepared statements for all SQL queries and properly escapes all output, which are crucial for preventing common web vulnerabilities like SQL injection and Cross-Site Scripting (XSS). The absence of dangerous functions, file operations, and external HTTP requests further minimizes the attack surface. A single nonce check is present, indicating some level of input validation is being performed. The plugin also has no recorded vulnerability history, suggesting a consistent track record of security awareness and implementation.
However, a significant concern arises from the lack of capability checks on its entry points. While the AJAX handlers and shortcodes are identified as entry points, the analysis indicates zero capability checks. This means that any authenticated user, regardless of their role or permissions, could potentially trigger these functionalities. This absence of authorization checks presents a significant risk, as it could allow for privilege escalation or unintended actions by low-privileged users. The taint analysis also shows zero flows, which is positive, but the lack of comprehensive input validation across all entry points, especially in the absence of capability checks, leaves room for potential exploitation if new vulnerabilities were introduced.
Key Concerns
- No capability checks on entry points
Shortcode Popup Forms Security Vulnerabilities
Shortcode Popup Forms Code Analysis
Output Escaping
Shortcode Popup Forms Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 9
Maintenance & Trust
Shortcode Popup Forms Maintenance & Trust
Maintenance Signals
Community Trust
Shortcode Popup Forms Alternatives
woo-shortcode-popup
woo-shortcode-popup
Creates a popup button on woocommerce shop page
Email addon for CF7
cf7-email-add-on
Email addon for CF7 plugin provides the responsive Email templates to admin and users.
Getsitecontrol — Email Marketing Plugin | Popup Maker, Automations & Newsletters
getsitecontrol
Complete email marketing toolset with a powerful popup builder on board. Generate leads with email opt-in forms, send professional newsletters, build …
Contact Form 7 Response Message Popup
contact-form-7-response-message-popup
Contact Form 7 Response Message in Fancybox Popup
SaleGen Marketing Toolkit
salegen-marketing-toolkit
Form, Popup, Email Marketing Builder with built-in Contacts CRM. Capture leads and send campaigns without third-party services.
Shortcode Popup Forms Developer Profile
2 plugins · 0 total installs
How We Detect Shortcode Popup Forms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shortcode-popup-forms/assets/css/thaxam-contact-form-admin.css/wp-content/plugins/shortcode-popup-forms/assets/css/thaxam-contact-form.css/wp-content/plugins/shortcode-popup-forms/assets/js/thaxam-contact-form-admin.js/wp-content/plugins/shortcode-popup-forms/assets/js/thaxam-contact-form.js/wp-content/plugins/shortcode-popup-forms/assets/js/thaxam-contact-form-admin.js/wp-content/plugins/shortcode-popup-forms/assets/js/thaxam-contact-form.jsthaxam-scf-admin-cssthaxam-scf-cssthaxam-scf-admin-jsthaxam-scf-jsHTML / DOM Fingerprints
thaxam-contact-form-wrapthaxam-contact-formthaxam-form-fieldthaxam-form-labelthaxam-form-inputthaxam-form-textareathaxam-form-submitdata-form-idthaxam_scf_ajax_object[thaxam-contact