Wavypoint Pop-Ups – Exit Intent, Marketing & Conversion Popup Builder Security & Risk Analysis

wordpress.org/plugins/wavypoint-pop-ups

Create high-converting popups in WordPress: exit intent, smart targeting, banners, and video popups to boost leads and sales.

0 active installs v1.0.3 PHP 7.2+ WP 5.2+ Updated Jun 6, 2026
exit-intent-popuppopuppopup-builderpopupswordpress-popup-plugin
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Wavypoint Pop-Ups – Exit Intent, Marketing & Conversion Popup Builder Safe to Use in 2026?

Generally Safe

Score 100/100

Wavypoint Pop-Ups – Exit Intent, Marketing & Conversion Popup Builder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "wavypoint-pop-ups" v1.0.0 plugin exhibits a strong security posture based on the provided static analysis. It demonstrates excellent practices with no identified dangerous functions, no raw SQL queries, and a very high percentage of properly escaped output. The absence of any identified taint flows, critical severity issues, or known vulnerabilities in its history further bolsters this positive assessment. This indicates a well-developed and security-conscious approach by the developers.

However, there is a single external HTTP request that lacks explicit details on authentication or authorization checks, which could potentially be a minor concern if it handles sensitive data or is susceptible to manipulation. While the overall attack surface is zero, the presence of this single external request warrants attention for thoroughness. The plugin's vulnerability history being completely clear is a significant strength, suggesting a low likelihood of past security oversights.

In conclusion, "wavypoint-pop-ups" v1.0.0 appears to be a highly secure plugin with excellent coding practices. The primary area for a slight cautionary note is the single external HTTP request, which would ideally have more detailed security checks outlined. The lack of any historical vulnerabilities is a very positive indicator of its current and likely future security.

Key Concerns

  • External HTTP request without clear auth/auth checks
Vulnerabilities
None known

Wavypoint Pop-Ups – Exit Intent, Marketing & Conversion Popup Builder Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Wavypoint Pop-Ups – Exit Intent, Marketing & Conversion Popup Builder Release Timeline

v1.0.3Current
v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

Wavypoint Pop-Ups – Exit Intent, Marketing & Conversion Popup Builder Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
250 escaped
Nonce Checks
7
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

98% escaped254 total outputs
Attack Surface

Wavypoint Pop-Ups – Exit Intent, Marketing & Conversion Popup Builder Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 14
actioninitinc/Base/CustomPostType.php:14
actionedit_form_after_titleinc/Base/CustomPostType.php:15
actionadd_meta_boxesinc/Base/CustomPostType.php:16
actionsave_postinc/Base/CustomPostType.php:17
actionedit_form_after_titleinc/Base/CustomPostType.php:18
filtermanage_wavypopup_posts_columnsinc/Base/CustomPostType.php:37
actionmanage_wavypopup_posts_custom_columninc/Base/CustomPostType.php:50
actionadmin_enqueue_scriptsinc/Base/CustomPostType.php:58
actionadmin_enqueue_scriptsinc/Base/CustomPostType.php:110
actionadmin_enqueue_scriptsinc/Base/CustomPostType.php:153
actionwp_enqueue_scriptsinc/Base/Enqueue.php:16
actionadmin_enqueue_scriptsinc/Base/Enqueue.php:17
actionwp_footerinc/Base/Frontend.php:14
actionadmin_menuinc/Pages/WavyBannerMaker.php:16
Maintenance & Trust

Wavypoint Pop-Ups – Exit Intent, Marketing & Conversion Popup Builder Maintenance & Trust

Maintenance Signals

WordPress version tested7.0.2
Last updatedJun 6, 2026
PHP min version7.2
Downloads381

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Wavypoint Pop-Ups – Exit Intent, Marketing & Conversion Popup Builder Developer Profile

wavypoint

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Wavypoint Pop-Ups – Exit Intent, Marketing & Conversion Popup Builder

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wavypoint-pop-ups/assets/css/style.css/wp-content/plugins/wavypoint-pop-ups/assets/js/wavypoint-popups.js
Script Paths
/wp-content/plugins/wavypoint-pop-ups/assets/js/wavypoint-popups.js
Version Parameters
wavypoint-pop-ups/assets/css/style.css?ver=wavypoint-pop-ups/assets/js/wavypoint-popups.js?ver=

HTML / DOM Fingerprints

CSS Classes
wavypopup-type-boxwavypopup-banner-box
Data Attributes
name="wavypopup_type"name="wavypopup_banner_url"name="popup_display_location"
JS Globals
WavypointPopUps
FAQ

Frequently Asked Questions about Wavypoint Pop-Ups – Exit Intent, Marketing & Conversion Popup Builder