Webside Popup Creator Security & Risk Analysis

wordpress.org/plugins/webside-popup-creator

Create simple popups with HTML or image content, triggered by time delay or scroll percentage. Lightweight and easy to configure.

10 active installs v1.2.7 PHP 7.4+ WP 5.0+ Updated Jun 22, 2025
marketingmodalpopupscroll-popuptimed-popup
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Webside Popup Creator Safe to Use in 2026?

Generally Safe

Score 100/100

Webside Popup Creator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10mo ago
Risk Assessment

The "webside-popup-creator" v1.2.7 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices in several key areas, including the absence of known CVEs, no use of raw SQL queries (all are prepared statements), and a clean vulnerability history. The plugin also includes some capability checks and a nonce check, which are essential for secure WordPress development. However, there are notable areas of concern. The static analysis reveals that only 40% of output is properly escaped, indicating a potential for cross-site scripting (XSS) vulnerabilities. Additionally, a taint analysis identified one flow with unsanitized paths, which, while not flagged as critical or high severity in this analysis, warrants attention as it could be a precursor to more severe issues if exploited in conjunction with other weaknesses. The presence of file operations also needs careful scrutiny, especially if the unsanitized path is related to file manipulation.

Key Concerns

  • Low output escaping percentage
  • Unsanitized path flow identified
  • File operations present
Vulnerabilities
None known

Webside Popup Creator Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Webside Popup Creator Release Timeline

v1.2.7Current
v1.2.6
Code Analysis
Analyzed Mar 17, 2026

Webside Popup Creator Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
100
66 escaped
Nonce Checks
1
Capability Checks
3
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

40% escaped166 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
webspop_debug (webside-popup-creator.php:1724)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Webside Popup Creator Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_menuwebside-popup-creator.php:50
actionadmin_initwebside-popup-creator.php:66
actionadmin_enqueue_scriptswebside-popup-creator.php:1103
actionwp_enqueue_scriptswebside-popup-creator.php:1153
actionwp_footerwebside-popup-creator.php:1384
actionplugins_loadedwebside-popup-creator.php:1699
actionadmin_bar_menuwebside-popup-creator.php:1769
actioninitwebside-popup-creator.php:1791
Maintenance & Trust

Webside Popup Creator Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 22, 2025
PHP min version7.4
Downloads457

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Webside Popup Creator Developer Profile

Andaç Güven

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Webside Popup Creator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/webside-popup-creator/css/webside-popup-creator.css/wp-content/plugins/webside-popup-creator/js/webside-popup-creator.js
Script Paths
/wp-content/plugins/webside-popup-creator/js/webside-popup-creator.js
Version Parameters
webside-popup-creator/css/webside-popup-creator.css?ver=webside-popup-creator/js/webside-popup-creator.js?ver=

HTML / DOM Fingerprints

CSS Classes
webspop-content-optionwebspop-trigger-optionwebspop-trigger-delay-1webspop-trigger-scroll-1webspop-content-html-1webspop-content-image-1webspop-cookie-option-1webspop-trigger-delay-2+8 more
Data Attributes
data-webspop-iddata-webspop-delaydata-webspop-scrolldata-webspop-content-typedata-webspop-cookie-durationdata-webspop-close-overlay
JS Globals
window.webspop_settings
FAQ

Frequently Asked Questions about Webside Popup Creator