Slick Popup: Contact Form 7 Popup Plugin Security & Risk Analysis

wordpress.org/plugins/slick-popup

A lightweight plugin that converts a Contact Form 7 form into a customizable pop-up form which is slick, beautiful and responsive to different screen …

2K active installs v1.7.16 PHP 7.2+ WP 3.5+ Updated Sep 24, 2025
cf7contact-form-7popuppopup-formwordpress-popup-plugin
99
A · Safe
CVEs total2
Unpatched0
Last CVEOct 29, 2023
Safety Verdict

Is Slick Popup: Contact Form 7 Popup Plugin Safe to Use in 2026?

Generally Safe

Score 99/100

Slick Popup: Contact Form 7 Popup Plugin has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Oct 29, 2023Updated 6mo ago
Risk Assessment

The slick-popup plugin, version 1.7.16, exhibits a mixed security posture. On the positive side, the static analysis reveals a commendable lack of direct attack vectors such as AJAX handlers, REST API routes, shortcodes, or cron events that are exposed without authentication or permission checks. Furthermore, the plugin demonstrates good practice by exclusively using prepared statements for its SQL queries, mitigating the risk of SQL injection. However, significant concerns arise from the output escaping, with only 4% of outputs being properly escaped. This indicates a high probability of Cross-Site Scripting (XSS) vulnerabilities where user-supplied input can be rendered in the browser without proper sanitization. The vulnerability history is also a critical area of concern, with two known CVEs, including one high and one medium severity vulnerability. The presence of 'Improper Neutralization of Input During Web Page Generation' and 'Use of Hard-coded Credentials' as common vulnerability types, coupled with a recent vulnerability in October 2023, suggests a pattern of insecure coding practices related to input handling and potentially credential management. Despite the absence of critical taint flows or dangerous functions in this specific static analysis, the history of severe vulnerabilities and the poor output escaping practices point to a plugin that requires careful scrutiny and timely updates to address potential security weaknesses.

Key Concerns

  • High percentage of unescaped output
  • One High severity CVE
  • One Medium severity CVE
  • Vulnerability history includes XSS
  • Vulnerability history includes Hard-coded Credentials
Vulnerabilities
2

Slick Popup: Contact Form 7 Popup Plugin Security Vulnerabilities

CVEs by Year

1 CVE in 2019
2019
1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

High
1
Medium
1

2 total CVEs

CVE-2023-46824medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Slick Popup: Contact Form 7 Popup Plugin <= 1.7.14 - Authenticated (Admin+) Stored Cross-Site Scripting

Oct 29, 2023 Patched in 1.7.15 (86d)
CVE-2019-15867high · 8.8Use of Hard-coded Credentials

Slick Popup <= 1.7.1 - Privilege Escalation

May 28, 2019 Patched in 1.7.2 (1701d)
Code Analysis
Analyzed Mar 16, 2026

Slick Popup: Contact Form 7 Popup Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
48
2 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

4% escaped50 total outputs
Attack Surface

Slick Popup: Contact Form 7 Popup Plugin Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionupgrader_process_completeslick-popup.php:71
actionredux/options/splite_opts/savedslick-popup.php:78
actiontemplate_redirectslick-popup.php:158
actionwp_enqueue_scriptsslick-popup.php:214
actionwp_footerslick-popup.php:215
actionwp_footerslick-popup.php:222
actionredux/page/splite_opts/enqueueslick-popup.php:529
actionadmin_enqueue_scriptsslick-popup.php:567
actionredux/page/splite_opts/menu/afterslick-popup.php:603
filteradmin_body_classslick-popup.php:635
Maintenance & Trust

Slick Popup: Contact Form 7 Popup Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 24, 2025
PHP min version7.2
Downloads80K

Community Trust

Rating94/100
Number of ratings22
Active installs2K
Developer Profile

Slick Popup: Contact Form 7 Popup Plugin Developer Profile

Ankit Singla

4 plugins · 2K total installs

71
trust score
Avg Security Score
89/100
Avg Patch Time
894 days
View full developer profile
Detection Fingerprints

How We Detect Slick Popup: Contact Form 7 Popup Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/slick-popup/libs/admin/css/custom.css/wp-content/plugins/slick-popup/libs/admin/css/redux-framework.css/wp-content/plugins/slick-popup/libs/admin/css/style.css/wp-content/plugins/slick-popup/libs/admin/img/popup-image.jpg/wp-content/plugins/slick-popup/libs/admin/js/admin-init.js/wp-content/plugins/slick-popup/libs/admin/js/custom.js/wp-content/plugins/slick-popup/libs/admin/js/redux-framework.js/wp-content/plugins/slick-popup/libs/admin/js/redux-manifest.js+7 more
Script Paths
/wp-content/plugins/slick-popup/libs/frontend/js/slick-popup.js
Version Parameters
/wp-content/plugins/slick-popup/libs/frontend/css/slick-popup.css?ver=/wp-content/plugins/slick-popup/libs/frontend/js/slick-popup.js?ver=

HTML / DOM Fingerprints

CSS Classes
splite-popup-content-wrappersplite-popup-closesplite-popup-side-imagesplite-popup-headingsplite-popup-form-wrap
HTML Comments
<!-- Empty Activation Hook --><!-- Empty Deactivation Hook --><!-- Empty Activation Hook --><!-- Temporary Fix -->+3 more
Data Attributes
data-splite-cf7-iddata-splite-redirect-urldata-splite-form-headingdata-splite-form-descriptiondata-splite-close-textdata-splite-side-image-alt+3 more
JS Globals
splite_frontend_localizesplite_opts
FAQ

Frequently Asked Questions about Slick Popup: Contact Form 7 Popup Plugin