PopCraft: Seamless Text Popovers in WordPress Security & Risk Analysis

wordpress.org/plugins/text-popover

Elevate your WordPress editing experience with the Text Popover plugin, designed to seamlessly integrate with various blocks featuring toolbars such a …

80 active installs v1.0.1 PHP 7.0+ WP 5.0+ Updated Jan 10, 2024
block-editorcontent-enhancementgutenbergtext-popoverwordpress
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is PopCraft: Seamless Text Popovers in WordPress Safe to Use in 2026?

Generally Safe

Score 85/100

PopCraft: Seamless Text Popovers in WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The 'text-popover' plugin v1.0.1 demonstrates a very strong security posture based on the provided static analysis results. There are no identified entry points like AJAX handlers, REST API routes, or shortcodes exposed to users, which significantly reduces the attack surface. The code also shows excellent adherence to secure coding practices, with no dangerous function calls, all SQL queries using prepared statements, and all output properly escaped. Furthermore, there are no file operations, external HTTP requests, or any indications of missed security checks like nonces or capability checks.

The lack of any identified taint flows, even with zero flows analyzed, suggests that if there were any, they would likely be well-sanitized. The plugin's vulnerability history is also pristine, with no recorded CVEs, indicating a lack of known security flaws over time. This clean record, coupled with the robust static analysis findings, points to a well-developed and secure plugin.

While the lack of entry points and comprehensive secure coding practices are significant strengths, the absence of any entry points at all could also imply limited functionality. However, based solely on the provided data, the plugin exhibits an exceptionally low risk profile. The primary concern, if any, would be the potential for future vulnerabilities if the plugin's functionality expands without maintaining these high security standards.

Vulnerabilities
None known

PopCraft: Seamless Text Popovers in WordPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

PopCraft: Seamless Text Popovers in WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

PopCraft: Seamless Text Popovers in WordPress Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actioninitpopover-tool.php:26
actionwp_enqueue_scriptspopover-tool.php:43
actionadmin_enqueue_scriptspopover-tool.php:53
Maintenance & Trust

PopCraft: Seamless Text Popovers in WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedJan 10, 2024
PHP min version7.0
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs80
Developer Profile

PopCraft: Seamless Text Popovers in WordPress Developer Profile

Chintesh Prajapati

5 plugins · 200 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect PopCraft: Seamless Text Popovers in WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/text-popover/assets/js/popovertool.min.js/wp-content/plugins/text-popover/assets/css/popovertool.min.css
Script Paths
/wp-content/plugins/text-popover/assets/js/popovertool.min.js
Version Parameters
popover_tool_js?ver=1.0popover_tool_css?ver=1.0

HTML / DOM Fingerprints

Data Attributes
data-toggle="text-popover"
FAQ

Frequently Asked Questions about PopCraft: Seamless Text Popovers in WordPress