
Smartarget Popup Security & Risk Analysis
wordpress.org/plugins/smartarget-popupAdd Popup window on your website
Is Smartarget Popup Safe to Use in 2026?
Mostly Safe
Score 79/100Smartarget Popup is generally safe to use. 1 past CVE were resolved. Keep it updated.
The static analysis of smartarget-popup v1.5 reveals a generally robust code structure, with no detected dangerous functions, all SQL queries using prepared statements, and proper output escaping. The attack surface is also remarkably clean, with zero entry points identified in AJAX handlers, REST API routes, shortcodes, or cron events. Taint analysis shows no identified flows with unsanitized paths. This indicates good development practices concerning common web vulnerabilities within the analyzed code.
However, the plugin's security posture is significantly undermined by its vulnerability history. The presence of one known, unpatched medium-severity CVE related to Cross-Site Scripting is a critical concern. The fact that this vulnerability is not patched suggests a lack of ongoing maintenance or timely security response from the developers. While the current code analysis shows no immediate exploitable flaws, the historical context of a previously exploited vulnerability, which remains unaddressed, poses a substantial risk to users.
In conclusion, while the code itself appears to follow secure coding guidelines, the unpatched vulnerability in its history is a serious weakness. Users should be highly cautious, as the potential for exploitation still exists. The absence of active security updates for known issues is a major red flag, overriding the positive aspects of the static code analysis.
Key Concerns
- Unpatched medium severity CVE
Smartarget Popup Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Smartarget Popup <= 1.4 - Authenticated (Administrator+) Stored Cross-Site Scripting
Smartarget Popup Code Analysis
Output Escaping
Smartarget Popup Attack Surface
WordPress Hooks 7
Maintenance & Trust
Smartarget Popup Maintenance & Trust
Maintenance Signals
Community Trust
Smartarget Popup Alternatives
Popup Builder – Create highly converting, mobile friendly marketing popups.
popup-builder
Increase Sales, Lead Generation, Conversion rates and receive good Call to Action rates with smart WordPress popup plugin.
Popup Box – Create Countdown, Coupon, Video, Contact Form Popups
ays-popup-box
Build flexible popups and modal windows with multiple popup types, triggers, and display controls.
Poptin – Exit Pop Ups & Email Popups
poptin
Free exit intent popup builder, gamified popups with spin the wheel, contact form builder & lead generation pop ups platform for your website. 🎉
Pop-up
pop-up-pop-up
Pop-up Popups
ITRO Popup Plugin
itro-popup
Display a popup to your WordPress site: age verification popup for adult-content site ★ multilanguage popup with qTransalte-X ★ very easy to use
Smartarget Popup Developer Profile
21 plugins · 2K total installs
How We Detect Smartarget Popup
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/smartarget-popup/css/smartarget.css/wp-content/plugins/smartarget-popup/js/smartarget-popup.jshttps://smartarget.online/loader.jssmartarget-popup/css/smartarget.css?ver=smartarget-popup/js/smartarget-popup.js?ver=HTML / DOM Fingerprints
smartarget-popup-wrapperst-close-btnst-overlay<!-- Smartarget Popup --><!-- Smartarget Close Button -->data-smartarget-iddata-smartarget-uidsmartargetPopup