
Wing Popup Security & Risk Analysis
wordpress.org/plugins/wing-popupPop up everything you like! Easily create informative and promotional popups. Boost your sales, lead generation, and conversions rates.
Is Wing Popup Safe to Use in 2026?
Generally Safe
Score 100/100Wing Popup has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of the "wing-popup" plugin version 1.0.2 indicates a generally strong security posture. The absence of identified AJAX handlers, REST API routes, shortcodes, and cron events suggests a minimal attack surface. Furthermore, the code signals show no dangerous functions, all SQL queries use prepared statements, and a high percentage of output is properly escaped. The lack of file operations and external HTTP requests also contributes positively to its security. The plugin also has no recorded vulnerability history, which is a positive indicator. However, the complete absence of nonce checks and capability checks is a significant concern. While the current analysis didn't reveal any exploitable vulnerabilities due to this, it leaves the plugin susceptible to various CSRF and privilege escalation attacks if any entry points are introduced in future updates or if sensitive actions are performed without proper authorization checks. This oversight represents a potential weakness that could be exploited.
Key Concerns
- Missing nonce checks
- Missing capability checks
- Low attack surface but no auth checks
Wing Popup Security Vulnerabilities
Wing Popup Code Analysis
Output Escaping
Wing Popup Attack Surface
WordPress Hooks 9
Maintenance & Trust
Wing Popup Maintenance & Trust
Maintenance Signals
Community Trust
Wing Popup Alternatives
Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder
popup-maker
Want to boost sales & marketing efforts? Use your favorite forms & builder. Unlimited popups & impressions, keep your data, no monthly subscription.
SendPulse – Popup Builder for Email Optins, Lead Generation, Sticky Bars and Videos
sendpulse-popups
SendPulse Pop-ups plugin for WordPress. Create highly converting and mobile-friendly pop-ups, opt-in forms, exit popups, sticky bars, NPS surveys, etc
I Love PopUps Connector
i-love-popups-connector
Lightweight connector that loads the official I Love PopUps script on your site using your Project ID.
Popup Builder & Popup Maker for WordPress – OptinMonster Email Marketing and Lead Generation
optinmonster
🤩 Make popups & optin forms to get more email newsletter subscribers, leads, and sales - #1 most popular popup builder plugin! 🚀
Advanced Popups
advanced-popups
Display high-converting newsletter popups, a cookie notice, or a notification with the light-weight yet feature-rich plugin.
Wing Popup Developer Profile
2 plugins · 0 total installs
How We Detect Wing Popup
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wing-popup/assets/css/frontend.css/wp-content/plugins/wing-popup/assets/js/frontend.js/wp-content/plugins/wing-popup/assets/css/backend.css/wp-content/plugins/wing-popup/assets/js/backend.js/wp-content/plugins/wing-popup/assets/libs/bootstrap/css/bootstrap.min.css/wp-content/plugins/wing-popup/assets/libs/bootstrap/js/bootstrap.min.js/wp-content/plugins/wing-popup/assets/libs/owl-carousel/owl.carousel.min.css/wp-content/plugins/wing-popup/assets/libs/owl-carousel/owl.carousel.min.js+1 more/wp-content/plugins/wing-popup/assets/js/frontend.js/wp-content/plugins/wing-popup/assets/js/backend.js/wp-content/plugins/wing-popup/assets/libs/bootstrap/js/bootstrap.min.js/wp-content/plugins/wing-popup/assets/libs/owl-carousel/owl.carousel.min.js/wp-content/plugins/wing-popup/assets/libs/sweetalert2/sweetalert2.min.jswing-popup/style.css?ver=wing-popup/script.js?ver=wing-popup/assets/css/frontend.css?ver=wing-popup/assets/js/frontend.js?ver=wing-popup/assets/css/backend.css?ver=wing-popup/assets/js/backend.js?ver=wing-popup/assets/libs/bootstrap/css/bootstrap.min.css?ver=wing-popup/assets/libs/bootstrap/js/bootstrap.min.js?ver=wing-popup/assets/libs/owl-carousel/owl.carousel.min.css?ver=wing-popup/assets/libs/owl-carousel/owl.carousel.min.js?ver=wing-popup/assets/libs/sweetalert2/sweetalert2.min.js?ver=HTML / DOM Fingerprints
wdpop-popup-containerwdpop-popup-wrapperwdpop-close-buttonwing-popup-wrap<!-- The core plugin class that is used to define internationalization,
* admin-specific hooks, and public-facing site hooks. --><!-- Begins execution of the plugin.
*
* Since everything within the plugin is registered via hooks,
* then kicking off the plugin from this point in the file does
* not affect the page life cycle.
*
* @since 1.0.0 --><!-- Helper class for Wing Popup --><!-- Static variable -->+2 moredata-wdpop-iddata-wdpop-triggerdata-wdpop-delaydata-wdpop-scrolldata-wdpop-exit-intentWDPOPwdpop_frontend_paramsWDPOP_Helper/wp-json/wdpop/v1/popup[wing_popup id="1"]