
Slick Popup: Contact Form 7 Popup Plugin Security & Risk Analysis
wordpress.org/plugins/slick-popupA lightweight plugin that converts a Contact Form 7 form into a customizable pop-up form which is slick, beautiful and responsive to different screen …
Is Slick Popup: Contact Form 7 Popup Plugin Safe to Use in 2026?
Generally Safe
Score 99/100Slick Popup: Contact Form 7 Popup Plugin has a strong security track record. Known vulnerabilities have been patched promptly.
The slick-popup plugin, version 1.7.16, exhibits a mixed security posture. On the positive side, the static analysis reveals a commendable lack of direct attack vectors such as AJAX handlers, REST API routes, shortcodes, or cron events that are exposed without authentication or permission checks. Furthermore, the plugin demonstrates good practice by exclusively using prepared statements for its SQL queries, mitigating the risk of SQL injection. However, significant concerns arise from the output escaping, with only 4% of outputs being properly escaped. This indicates a high probability of Cross-Site Scripting (XSS) vulnerabilities where user-supplied input can be rendered in the browser without proper sanitization. The vulnerability history is also a critical area of concern, with two known CVEs, including one high and one medium severity vulnerability. The presence of 'Improper Neutralization of Input During Web Page Generation' and 'Use of Hard-coded Credentials' as common vulnerability types, coupled with a recent vulnerability in October 2023, suggests a pattern of insecure coding practices related to input handling and potentially credential management. Despite the absence of critical taint flows or dangerous functions in this specific static analysis, the history of severe vulnerabilities and the poor output escaping practices point to a plugin that requires careful scrutiny and timely updates to address potential security weaknesses.
Key Concerns
- High percentage of unescaped output
- One High severity CVE
- One Medium severity CVE
- Vulnerability history includes XSS
- Vulnerability history includes Hard-coded Credentials
Slick Popup: Contact Form 7 Popup Plugin Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Slick Popup: Contact Form 7 Popup Plugin <= 1.7.14 - Authenticated (Admin+) Stored Cross-Site Scripting
Slick Popup <= 1.7.1 - Privilege Escalation
Slick Popup: Contact Form 7 Popup Plugin Code Analysis
Output Escaping
Slick Popup: Contact Form 7 Popup Plugin Attack Surface
WordPress Hooks 10
Maintenance & Trust
Slick Popup: Contact Form 7 Popup Plugin Maintenance & Trust
Maintenance Signals
Community Trust
Slick Popup: Contact Form 7 Popup Plugin Alternatives
WPB Popup for Contact Form 7 – Showing The Contact Form 7 Popup on Button Click – CF7 Popup
wpb-popup-for-contact-form-7
Popup for Contact Form 7 can boost your sales, leads, and conversions. It only takes a few clicks to setup a Contact Form 7 Popup on Button Click.
Popups – Submission Messages For Contact Form 7
cf7-popups
Display contact form 7 default messages in stylish popup as user submits the form.
Popup for CF7 with Sweet Alert
cf7-sweet-alert-popup
Popup for CF7 with Sweet Alert
Form Popup Maker for WPForms, Contact Form 7 and Many other Forms
wpb-form-popup
WPB Popup Form WordPress plugin will help you to create effective form popups. WPForms Popup form, Mailchimp popup, Opt-in, login popup.
Database Addon for Contact Form 7 – CFDB7
contact-form-cfdb7
Save and manage Contact Form 7 messages. Never lose important data. It is a lightweight contact form 7 database plugin.
Slick Popup: Contact Form 7 Popup Plugin Developer Profile
4 plugins · 2K total installs
How We Detect Slick Popup: Contact Form 7 Popup Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/slick-popup/libs/admin/css/custom.css/wp-content/plugins/slick-popup/libs/admin/css/redux-framework.css/wp-content/plugins/slick-popup/libs/admin/css/style.css/wp-content/plugins/slick-popup/libs/admin/img/popup-image.jpg/wp-content/plugins/slick-popup/libs/admin/js/admin-init.js/wp-content/plugins/slick-popup/libs/admin/js/custom.js/wp-content/plugins/slick-popup/libs/admin/js/redux-framework.js/wp-content/plugins/slick-popup/libs/admin/js/redux-manifest.js+7 more/wp-content/plugins/slick-popup/libs/frontend/js/slick-popup.js/wp-content/plugins/slick-popup/libs/frontend/css/slick-popup.css?ver=/wp-content/plugins/slick-popup/libs/frontend/js/slick-popup.js?ver=HTML / DOM Fingerprints
splite-popup-content-wrappersplite-popup-closesplite-popup-side-imagesplite-popup-headingsplite-popup-form-wrap<!-- Empty Activation Hook --><!-- Empty Deactivation Hook --><!-- Empty Activation Hook --><!-- Temporary Fix -->+3 moredata-splite-cf7-iddata-splite-redirect-urldata-splite-form-headingdata-splite-form-descriptiondata-splite-close-textdata-splite-side-image-alt+3 moresplite_frontend_localizesplite_opts