
Smart Modal – Create Custom Popups with Trigger Options Security & Risk Analysis
wordpress.org/plugins/smart-modalModal builder block. Create popup/modal easily.
Is Smart Modal – Create Custom Popups with Trigger Options Safe to Use in 2026?
Generally Safe
Score 100/100Smart Modal – Create Custom Popups with Trigger Options has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'smart-modal' plugin v1.0.5 presents a mixed security profile. On the positive side, it demonstrates good practices by exclusively using prepared statements for SQL queries and has no recorded vulnerabilities (CVEs) or known dangerous functions. The limited attack surface, with only one shortcode and no unprotected entry points identified in the static analysis, also contributes to a generally favorable security posture. However, a significant concern arises from the complete lack of output escaping. This means that any data displayed through the plugin, even if sourced internally, is not being sanitized for potentially malicious content, opening the door for cross-site scripting (XSS) attacks. Additionally, the absence of nonce checks, while not directly flagged as a vulnerability due to the limited attack surface, is a missed opportunity for robust security in handlers that process user input, making them potentially vulnerable if new AJAX or REST API endpoints were added without proper authorization checks. The absence of any taint flow analysis results is also notable; it's unclear if this indicates no exploitable flows were found or if the analysis was not comprehensive. Overall, while the plugin avoids common SQL injection and code execution risks, the unescaped output is a critical weakness that needs immediate attention.
Key Concerns
- All output is unescaped
- Missing nonce checks
Smart Modal – Create Custom Popups with Trigger Options Security Vulnerabilities
Smart Modal – Create Custom Popups with Trigger Options Release Timeline
Smart Modal – Create Custom Popups with Trigger Options Code Analysis
Output Escaping
Smart Modal – Create Custom Popups with Trigger Options Attack Surface
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
Smart Modal – Create Custom Popups with Trigger Options Maintenance & Trust
Maintenance Signals
Community Trust
Smart Modal – Create Custom Popups with Trigger Options Alternatives
Lightbox & Modal Popup WordPress Plugin – FooBox
foobox-image-lightbox
A responsive image lightbox for WordPress galleries, WordPress attachments & FooGallery
Modal Guten Block
modal-block
This plugin provides a Gutenberg Modal / Popup Block.
Light Modal Block
light-modal-block
Lightweight, customizable modal block for the WordPress block editor
MakeITeasy Popup
makeiteasy-popup
Advanced block based pop-up solution.
Nelio Popups
nelio-popups
An intuitive popup designer based on open WordPress technologies
Smart Modal – Create Custom Popups with Trigger Options Developer Profile
121 plugins · 740K total installs
How We Detect Smart Modal – Create Custom Popups with Trigger Options
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/smart-modal/assets/css/admin.css/wp-content/plugins/smart-modal/assets/js/admin.js/wp-content/plugins/smart-modal/assets/js/admin.jssmart-modal/assets/css/admin.css?ver=smart-modal/assets/js/admin.js?ver=HTML / DOM Fingerprints
bpsmbFrontShortcodetooltipdata-block="bpsmb/smart-modal-block"bsbHandleShortcode/wp-json/wp/v2/bpsmb[bpsmb-smart-modal id=