
Tsu Popup Security & Risk Analysis
wordpress.org/plugins/tsu-popupAdd your own tsu ( Social Network ) popup in any website.
Is Tsu Popup Safe to Use in 2026?
Generally Safe
Score 85/100Tsu Popup has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "tsu-popup" v1.0 plugin exhibits a mixed security posture. On one hand, the absence of known CVEs and a clean taint analysis suggest a generally secure codebase with no immediately obvious critical vulnerabilities. The plugin also demonstrates good practices by utilizing prepared statements for all SQL queries. However, significant concerns arise from the static analysis. The presence of the `create_function` dangerous function is a notable weakness, as it can be a vector for code injection if user-supplied input is passed to it without proper sanitization. Furthermore, a substantial portion of output (80%) is not properly escaped, creating a high risk of Cross-Site Scripting (XSS) vulnerabilities across various display points within the plugin. The lack of nonce checks and capability checks on potential entry points, coupled with a zero-count for these, indicates a potential oversight in securing user interactions.
Key Concerns
- Use of dangerous function `create_function`
- High percentage of unescaped output
- Missing nonce checks on entry points
- Missing capability checks on entry points
Tsu Popup Security Vulnerabilities
Tsu Popup Release Timeline
Tsu Popup Code Analysis
Dangerous Functions Found
Output Escaping
Tsu Popup Attack Surface
WordPress Hooks 6
Maintenance & Trust
Tsu Popup Maintenance & Trust
Maintenance Signals
Community Trust
Tsu Popup Alternatives
Tsu
tsu
Tsu widget to share your profile / invitation with your readers.
Invite Anyone
invite-anyone
Makes BuddyPress's invitation features more powerful.
WP eCards – Branded Digital Greeting Cards
wp-ecards-invites
Add interactive digital greeting cards to your WordPress site — fully branded, customizable, and shareable by visitors through email or social media.
Social Media Engine
social-media-engine
Social follow links shortcode. Built on FontAwesome icons. 30 social networks supported: 500px, behance, bitbucket, delicious, deviantart, digg, drib …
Invitations for Slack
invitations-for-slack
Build a Slack community by allowing your visitors (or registered users) to invite themselves to your Slack team.
Tsu Popup Developer Profile
1 plugin · 10 total installs
How We Detect Tsu Popup
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tsu-popup/css/style.css/wp-content/plugins/tsu-popup/js/main.js/wp-content/plugins/tsu-popup/js/main.jstsu-popup/css/style.css?ver=tsu-popup/js/main.js?ver=HTML / DOM Fingerprints
tsu-popuptsu-popup-closedata-tsu-usernamedata-tsu-usernamedata-tsu-display_namedata-tsu-titledata-tsu-descdata-tsu-logo+11 moretsu_popup_options