
What’s New Popup Generator Security & Risk Analysis
wordpress.org/plugins/whats-new-popup-generatorThis plugin will popup what's new section. You can make ten lines by your own and also adding links. What's new button can be created insid …
Is What’s New Popup Generator Safe to Use in 2026?
Generally Safe
Score 85/100What’s New Popup Generator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "whats-new-popup-generator" plugin v1.0.2 demonstrates a generally good security posture based on the provided static analysis. The absence of known vulnerabilities (CVEs) and the limited attack surface are positive indicators. Furthermore, the plugin correctly utilizes prepared statements for all SQL queries, which is a crucial security practice. However, a significant concern is the relatively low percentage (59%) of properly escaped output. This could potentially lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is displayed without sufficient sanitization. While no critical taint flows were identified, the unescaped output represents a potential avenue for exploitation.
The plugin's vulnerability history is clean, indicating a historical commitment to security or simply a lack of past discovered issues. The sole entry point identified is a shortcode, which, in this analysis, is not unprotected. The absence of unprotected AJAX handlers and REST API routes is commendable. The presence of a nonce check is also a positive sign, though it's not tied to any capability checks in this analysis, which could be a missed opportunity for more granular access control. Overall, the plugin is not inherently insecure but requires attention to its output escaping to mitigate potential XSS risks.
Key Concerns
- Significant portion of output not properly escaped
What’s New Popup Generator Security Vulnerabilities
What’s New Popup Generator Code Analysis
Output Escaping
Data Flow Analysis
What’s New Popup Generator Attack Surface
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
What’s New Popup Generator Maintenance & Trust
Maintenance Signals
Community Trust
What’s New Popup Generator Alternatives
Modal Popup Box: A Flexible Pop Up Box Builder
modal-popup-box
Create and manage a customizable pop up box on your WordPress website. Embed anything from videos and images to forms and shortcodes.
Popup Builder – Create highly converting, mobile friendly marketing popups.
popup-builder
Increase Sales, Lead Generation, Conversion rates and receive good Call to Action rates with smart WordPress popup plugin.
Claspo – Popups, Spin the Wheel & Email Capture
claspo
Grow your email list and increase sales! Use the Claspo Popup Maker plugin to create pop-up windows, Spin the Wheel, Exit Intent, and Lead Gen forms.
Experto CTA Widget – Call To Action, Sticky CTA, Floating Button Plugin
experto-cta-widget
Experto CTA Widget is a lightweight, easy-to-use plugin that comes with lots of customization options and create a popup widget with some contact form …
Popup – Popup Maker
popup-wp
Popup - Popup Maker makes it a breeze to convert visitors into leads, subscribers, and sales! Convert leads into customers.
What’s New Popup Generator Developer Profile
5 plugins · 7K total installs
How We Detect What’s New Popup Generator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/whats-new-popup-generator/css/popup_style.css/wp-content/plugins/whats-new-popup-generator/js/pop_colorPicker.jsHTML / DOM Fingerprints
popup_information_boxpopup_contents-overlaycursor:pointerborder: solid #a4a4a4 1pxtext-align:centerbackground-colorjQuery<div class="popup_information_box" style="cursor:pointer;border: solid #a4a4a4 1px; padding:px; width:px;text-align:center;color:;background-color: