
woo-shortcode-popup Security & Risk Analysis
wordpress.org/plugins/woo-shortcode-popupCreates a popup button on woocommerce shop page
Is woo-shortcode-popup Safe to Use in 2026?
Generally Safe
Score 85/100woo-shortcode-popup has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of woo-shortcode-popup v20160706.1 reveals an exceptionally clean codebase with no identified attack surface points, dangerous functions, file operations, or external HTTP requests. The use of prepared statements for all SQL queries is a strong security practice. Furthermore, the absence of known vulnerabilities in its history suggests a stable and well-maintained plugin. However, the low percentage of properly escaped output (63%) and the lack of capability checks are areas of concern. While the limited attack surface might mitigate the immediate impact of unescaped output, it still represents a potential vector for cross-site scripting (XSS) vulnerabilities if any user-supplied data reaches the output functions without proper sanitization. The presence of a nonce check, albeit only one, is a positive sign, but its limited scope might not cover all necessary operations.
Overall, the plugin exhibits a good security posture due to its minimal attack surface and robust handling of database queries. The lack of historical vulnerabilities is reassuring. However, the unescaped output presents a latent risk that could be exploited if the plugin evolves or its usage context changes. The absence of capability checks means that even authenticated users could potentially trigger unintended actions if vulnerabilities exist within the limited code pathways. The strengths lie in its minimal attack surface and secure database interactions, while the primary weakness is the incomplete output escaping.
Key Concerns
- Low percentage of properly escaped output
- No capability checks found
woo-shortcode-popup Security Vulnerabilities
woo-shortcode-popup Code Analysis
Output Escaping
woo-shortcode-popup Attack Surface
WordPress Hooks 4
Maintenance & Trust
woo-shortcode-popup Maintenance & Trust
Maintenance Signals
Community Trust
woo-shortcode-popup Alternatives
Contact Dialog
contact-dialog
Enables display of an AJAX driven contact form when a user clicks on links with a specified class.
General Contact Form
general-contact-form
Genaral Contact From plugin allows a wordpress admin to easily create and add contact forms to WordPress. The General Contact Form will let the user s …
WP Armour – Honeypot Anti Spam
honeypot
Fastest growing Anti Spam plugin. No API calls, subscriptions, captcha or puzzle. Full GDPR complaint. For comments, contact form, login, registration
Spam protection, Honeypot, Anti-Spam by CleanTalk
cleantalk-spam-protect
Blocks spam comments, fake users, contact form spam and more. No impact on SEO. Privacy focused. CAPTCHA free, premium Antispam plugin.
ReCaptcha v2 for Contact Form 7
wpcf7-recaptcha
Adds reCaptcha v2 from Contact Form 7 5.0.5 that was dropped on Contact Form 7 5.1
woo-shortcode-popup Developer Profile
1 plugin · 10 total installs
How We Detect woo-shortcode-popup
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woo-shortcode-popup/assets/style.csswoo-shortcode-popup/assets/style.css?ver=HTML / DOM Fingerprints
wsp-shortcode-popupdata-wsp-shortcode[wsp_button]