Smartarget Popup Security & Risk Analysis

wordpress.org/plugins/smartarget-popup

Add Popup window on your website

20 active installs v1.5 PHP 5.2.4+ WP 3.0.1+ Updated Feb 13, 2026
pop-uppopspoptinpopuppopup-message
79
B · Generally Safe
CVEs total1
Unpatched1
Last CVEApr 1, 2025
Safety Verdict

Is Smartarget Popup Safe to Use in 2026?

Mostly Safe

Score 79/100

Smartarget Popup is generally safe to use. 1 past CVE were resolved. Keep it updated.

1 known CVE 1 unpatched Last CVE: Apr 1, 2025Updated 1mo ago
Risk Assessment

The static analysis of smartarget-popup v1.5 reveals a generally robust code structure, with no detected dangerous functions, all SQL queries using prepared statements, and proper output escaping. The attack surface is also remarkably clean, with zero entry points identified in AJAX handlers, REST API routes, shortcodes, or cron events. Taint analysis shows no identified flows with unsanitized paths. This indicates good development practices concerning common web vulnerabilities within the analyzed code.

However, the plugin's security posture is significantly undermined by its vulnerability history. The presence of one known, unpatched medium-severity CVE related to Cross-Site Scripting is a critical concern. The fact that this vulnerability is not patched suggests a lack of ongoing maintenance or timely security response from the developers. While the current code analysis shows no immediate exploitable flaws, the historical context of a previously exploited vulnerability, which remains unaddressed, poses a substantial risk to users.

In conclusion, while the code itself appears to follow secure coding guidelines, the unpatched vulnerability in its history is a serious weakness. Users should be highly cautious, as the potential for exploitation still exists. The absence of active security updates for known issues is a major red flag, overriding the positive aspects of the static code analysis.

Key Concerns

  • Unpatched medium severity CVE
Vulnerabilities
1

Smartarget Popup Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-31853medium · 5.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Smartarget Popup <= 1.4 - Authenticated (Administrator+) Stored Cross-Site Scripting

Apr 1, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Smartarget Popup Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped4 total outputs
Attack Surface

Smartarget Popup Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionplugins_loadedincludes\class-smartarget-popup.php:142
actionadmin_enqueue_scriptsincludes\class-smartarget-popup.php:157
actionadmin_enqueue_scriptsincludes\class-smartarget-popup.php:158
actionadmin_menuincludes\class-smartarget-popup.php:160
actionadmin_initincludes\class-smartarget-popup.php:165
actionwp_enqueue_scriptsincludes\class-smartarget-popup.php:179
actionwp_enqueue_scriptsincludes\class-smartarget-popup.php:180
Maintenance & Trust

Smartarget Popup Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 13, 2026
PHP min version5.2.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Smartarget Popup Developer Profile

Erez Hadas-Sonnenschein

21 plugins · 2K total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Smartarget Popup

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/smartarget-popup/css/smartarget.css/wp-content/plugins/smartarget-popup/js/smartarget-popup.js
Script Paths
https://smartarget.online/loader.js
Version Parameters
smartarget-popup/css/smartarget.css?ver=smartarget-popup/js/smartarget-popup.js?ver=

HTML / DOM Fingerprints

CSS Classes
smartarget-popup-wrapperst-close-btnst-overlay
HTML Comments
<!-- Smartarget Popup --><!-- Smartarget Close Button -->
Data Attributes
data-smartarget-iddata-smartarget-uid
JS Globals
smartargetPopup
FAQ

Frequently Asked Questions about Smartarget Popup