WP Modal Popup with Cookie Integration Security & Risk Analysis

wordpress.org/plugins/wp-modal-popup-with-cookie-integration

WP Modal Popup with Cookie Integration is the smart, responsive, customizable and beautifully coded popup for visitors with cookie integration.

1K active installs v2.5 PHP + WP 4.0+ Updated Jul 16, 2025
advertiselightboxmarketingpop-overpop-up
98
A · Safe
CVEs total2
Unpatched0
Last CVEJul 30, 2025
Safety Verdict

Is WP Modal Popup with Cookie Integration Safe to Use in 2026?

Generally Safe

Score 98/100

WP Modal Popup with Cookie Integration has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Jul 30, 2025Updated 8mo ago
Risk Assessment

The plugin 'wp-modal-popup-with-cookie-integration' v2.5 exhibits a mixed security posture. The static analysis reveals a commendable effort in limiting its attack surface, with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are exposed. The absence of dangerous functions and file operations further strengthens its core security. However, the presence of 100% of SQL queries using prepared statements is a significant positive indicator. The main concern arises from the output escaping, where 72% of outputs are properly escaped, leaving a notable portion (28%) potentially vulnerable to Cross-Site Scripting (XSS) attacks. The vulnerability history shows two past medium-severity CVEs, both related to XSS, which highlights a recurring pattern. While there are currently no unpatched vulnerabilities, the historical trend of XSS issues, coupled with the incomplete output escaping, suggests a continued need for vigilance. The lack of nonce checks on any entry points is a significant oversight, as is the single capability check which may not be sufficient for all operations. Overall, the plugin has good foundational security practices in place but suffers from potential XSS risks due to incomplete output sanitization and a lack of robust authorization checks on its entry points.

Key Concerns

  • Incomplete output escaping (28% unescaped)
  • No nonce checks on entry points
  • Past medium-severity XSS vulnerabilities
Vulnerabilities
2

WP Modal Popup with Cookie Integration Security Vulnerabilities

CVEs by Year

2 CVEs in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2025-54683medium · 5.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WP Modal Popup with Cookie Integration <= 2.4 - Authenticated (Administrator+) Stored Cross-Site Scripting

Jul 30, 2025 Patched in 2.5 (6d)
CVE-2025-31772medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WP Modal Popup with Cookie Integration <= 2.4 - Authenticated (Administrator+) Stored Cross-Site Scripting

Apr 1, 2025 Patched in 2.5 (108d)
Code Analysis
Analyzed Mar 16, 2026

WP Modal Popup with Cookie Integration Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
13
34 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

72% escaped47 total outputs
Attack Surface

WP Modal Popup with Cookie Integration Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionadmin_menuincludes\admin\class-wmpci-admin.php:19
actionadmin_initincludes\admin\class-wmpci-admin.php:22
actionwp_footerincludes\class-wmpci-public.php:19
actionwp_enqueue_scriptsincludes\class-wmpci-script.php:19
actionwp_enqueue_scriptsincludes\class-wmpci-script.php:22
actionadmin_enqueue_scriptsincludes\class-wmpci-script.php:25
actionadmin_enqueue_scriptsincludes\class-wmpci-script.php:28
actioninitincludes\wmpci-post-types.php:58
actionplugins_loadedwp-modal-popup.php:53
actionupdate_option_active_pluginswp-modal-popup.php:97
actionadmin_noticeswp-modal-popup.php:127
Maintenance & Trust

WP Modal Popup with Cookie Integration Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJul 16, 2025
PHP min version
Downloads80K

Community Trust

Rating90/100
Number of ratings8
Active installs1K
Developer Profile

WP Modal Popup with Cookie Integration Developer Profile

Astoundify

10 plugins · 23K total installs

81
trust score
Avg Security Score
90/100
Avg Patch Time
31 days
View full developer profile
Detection Fingerprints

How We Detect WP Modal Popup with Cookie Integration

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-modal-popup-with-cookie-integration/assets/css/wmpci-public.css/wp-content/plugins/wp-modal-popup-with-cookie-integration/assets/js/wmpci-popup.js/wp-content/plugins/wp-modal-popup-with-cookie-integration/assets/js/wmpci-admin.js
Script Paths
/wp-content/plugins/wp-modal-popup-with-cookie-integration/assets/js/wmpci-popup.js/wp-content/plugins/wp-modal-popup-with-cookie-integration/assets/js/wmpci-admin.js
Version Parameters
wp-modal-popup-with-cookie-integration/assets/css/wmpci-public.css?ver=wp-modal-popup-with-cookie-integration/assets/js/wmpci-popup.js?ver=wp-modal-popup-with-cookie-integration/assets/js/wmpci-admin.js?ver=

HTML / DOM Fingerprints

JS Globals
Wmpci_PopupWmpci_Admin
FAQ

Frequently Asked Questions about WP Modal Popup with Cookie Integration