
Website Pop-up Builder by BDOW! (formerly Sumo): Pop-ups + forms for email opt-ins and lead generation Security & Risk Analysis
wordpress.org/plugins/sumomeSumo is trusted by over 600,000 businesses — small and large — in growing their email lists, customer base, and revenue online.
Is Website Pop-up Builder by BDOW! (formerly Sumo): Pop-ups + forms for email opt-ins and lead generation Safe to Use in 2026?
Generally Safe
Score 100/100Website Pop-up Builder by BDOW! (formerly Sumo): Pop-ups + forms for email opt-ins and lead generation has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The Sumome plugin v1.44 exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries, exclusively using prepared statements, and has no reported unpatched vulnerabilities, indicating active maintenance or a lack of recent critical flaws. The absence of dangerous functions and external HTTP requests further strengthens its security profile. However, significant concerns arise from its attack surface. With a total of 9 AJAX handlers, 7 of which lack authentication checks, there is a substantial opportunity for unauthorized actions if these handlers are exploitable. The taint analysis, while limited in scope, revealed one flow with an unsanitized path, which could potentially lead to vulnerabilities if further investigation uncovers exploitable paths. The plugin's vulnerability history, though showing only medium-severity issues in the past, is a reminder that even well-maintained plugins can have weaknesses. The presence of past CSRF vulnerabilities, though currently patched, warrants continued vigilance, especially concerning any new AJAX handlers without proper CSRF protection.
Key Concerns
- AJAX handlers without auth checks
- Flows with unsanitized paths
- Medium severity vulnerability in history
- File operations present
- Missing nonce checks on AJAX
Website Pop-up Builder by BDOW! (formerly Sumo): Pop-ups + forms for email opt-ins and lead generation Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Sumo <= 1.34 - Cross-Site Request Forgery
Website Pop-up Builder by BDOW! (formerly Sumo): Pop-ups + forms for email opt-ins and lead generation Release Timeline
Website Pop-up Builder by BDOW! (formerly Sumo): Pop-ups + forms for email opt-ins and lead generation Code Analysis
Output Escaping
Data Flow Analysis
Website Pop-up Builder by BDOW! (formerly Sumo): Pop-ups + forms for email opt-ins and lead generation Attack Surface
AJAX Handlers 9
WordPress Hooks 8
Maintenance & Trust
Website Pop-up Builder by BDOW! (formerly Sumo): Pop-ups + forms for email opt-ins and lead generation Maintenance & Trust
Maintenance Signals
Community Trust
Website Pop-up Builder by BDOW! (formerly Sumo): Pop-ups + forms for email opt-ins and lead generation Alternatives
Klaviyo
klaviyo
Klaviyo for WooCommerce
MailerLite – WooCommerce integration
woo-mailerlite
Powerful e-commerce email marketing tools that are easy to use. Grow your store with automated emails, pop-ups, product blocks, sales tracking + more.
ActiveCampaign for WooCommerce
activecampaign-for-woocommerce
Autonomous marketing to transform your store. Fuel your customer journeys with personalized experiences across email, SMS, and WhatsApp.
Email marketing for WordPress by GetResponse Official
getresponse-official
Maximize visitor potential! Capture emails, automate marketing, track visits, and transfer ecommerce data to GetResponse for precision campaigns.
Drip – Marketing Automation for WooCommerce
drip
Build long-lasting relationships with perfectly personalized email and onsite marketing automation.
Website Pop-up Builder by BDOW! (formerly Sumo): Pop-ups + forms for email opt-ins and lead generation Developer Profile
1 plugin · 20K total installs
How We Detect Website Pop-up Builder by BDOW! (formerly Sumo): Pop-ups + forms for email opt-ins and lead generation
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sumome/js/sumome-admin.js/wp-content/plugins/sumome/css/sumome-admin.cssHTML / DOM Fingerprints
sumome-site-iddata-sumo-site-idsumome_generate_site_idWP_Plugin_SumoMe/wp-json/sumome/