
Form Popup Maker for WPForms, Contact Form 7 and Many other Forms Security & Risk Analysis
wordpress.org/plugins/wpb-form-popupWPB Popup Form WordPress plugin will help you to create effective form popups. WPForms Popup form, Mailchimp popup, Opt-in, login popup.
Is Form Popup Maker for WPForms, Contact Form 7 and Many other Forms Safe to Use in 2026?
Generally Safe
Score 100/100Form Popup Maker for WPForms, Contact Form 7 and Many other Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wpb-form-popup plugin v1.3.2 exhibits a generally strong security posture based on the provided static analysis. The complete absence of raw SQL queries, a very high percentage of properly escaped output, and no file operations or external HTTP requests are excellent indicators of secure coding practices. The presence of nonce checks on all identified entry points further strengthens its defenses, suggesting an awareness of common WordPress vulnerabilities.
However, a notable concern arises from the taint analysis, which identified two flows with unsanitized paths. While these are not flagged as critical or high severity, unsanitized paths can still lead to potential vulnerabilities if the data is later processed in an unsafe manner. The absence of capability checks on AJAX handlers is another area that warrants attention. Although nonce checks are present, lacking explicit capability checks means that any user, regardless of their role or permissions, could potentially trigger these AJAX actions, which could be exploited if any of the AJAX actions have unintended side effects or expose sensitive information.
The plugin's vulnerability history is currently clean, with no known CVEs. This, combined with the positive coding signals, suggests a well-maintained and potentially secure plugin. The plugin's strengths lie in its robust SQL handling and output escaping. The primary weaknesses are the identified unsanitized paths in the taint analysis and the lack of capability checks on AJAX handlers, which represent the most significant areas for potential improvement and risk mitigation.
Key Concerns
- Unsanitized paths found in taint analysis
- Capability checks missing on AJAX handlers
Form Popup Maker for WPForms, Contact Form 7 and Many other Forms Security Vulnerabilities
Form Popup Maker for WPForms, Contact Form 7 and Many other Forms Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Form Popup Maker for WPForms, Contact Form 7 and Many other Forms Attack Surface
AJAX Handlers 6
Shortcodes 1
WordPress Hooks 14
Maintenance & Trust
Form Popup Maker for WPForms, Contact Form 7 and Many other Forms Maintenance & Trust
Maintenance Signals
Community Trust
Form Popup Maker for WPForms, Contact Form 7 and Many other Forms Alternatives
WPB Popup for Contact Form 7 – Showing The Contact Form 7 Popup on Button Click – CF7 Popup
wpb-popup-for-contact-form-7
Popup for Contact Form 7 can boost your sales, leads, and conversions. It only takes a few clicks to setup a Contact Form 7 Popup on Button Click.
Popup for CF7 with Sweet Alert
cf7-sweet-alert-popup
Popup for CF7 with Sweet Alert
Slick Popup: Contact Form 7 Popup Plugin
slick-popup
A lightweight plugin that converts a Contact Form 7 form into a customizable pop-up form which is slick, beautiful and responsive to different screen …
Popups – Submission Messages For Contact Form 7
cf7-popups
Display contact form 7 default messages in stylish popup as user submits the form.
Message Popup For Contact Form 7
message-popup-for-contact-form-7
Message Popup For Contact Form 7 to make the best way to set up popup on success and failed messages. After submitting form Open Popup in contact form …
Form Popup Maker for WPForms, Contact Form 7 and Many other Forms Developer Profile
25 plugins · 40K total installs
How We Detect Form Popup Maker for WPForms, Contact Form 7 and Many other Forms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpb-form-popup/assets/css/wpb-form-popup.css/wp-content/plugins/wpb-form-popup/assets/js/wpb-form-popup.js/wp-content/plugins/wpb-form-popup/assets/css/owl.carousel.min.css/wp-content/plugins/wpb-form-popup/assets/css/owl.theme.default.min.css/wp-content/plugins/wpb-form-popup/assets/js/owl.carousel.min.js/wp-content/plugins/wpb-form-popup/assets/js/jquery.magnific-popup.min.js/wp-content/plugins/wpb-form-popup/assets/js/wpb-form-popup-admin.js/wp-content/plugins/wpb-form-popup/assets/js/wpb-form-popup.js/wp-content/plugins/wpb-form-popup/assets/js/owl.carousel.min.js/wp-content/plugins/wpb-form-popup/assets/js/jquery.magnific-popup.min.js/wp-content/plugins/wpb-form-popup/assets/js/wpb-form-popup-admin.jswpb-form-popup/assets/css/wpb-form-popup.css?ver=wpb-form-popup/assets/js/wpb-form-popup.js?ver=wpb-form-popup/assets/css/owl.carousel.min.css?ver=wpb-form-popup/assets/css/owl.theme.default.min.css?ver=wpb-form-popup/assets/js/owl.carousel.min.js?ver=wpb-form-popup/assets/js/jquery.magnific-popup.min.js?ver=wpb-form-popup/assets/js/wpb-form-popup-admin.js?ver=HTML / DOM Fingerprints
wpbean-fopo-discount-noticewpbean-fopo-noticewpbean-fopo-pro-discount-dismissedwpb-form-popup-shortcode-elementdata-wpb-fopo-popup-id[wpb-form-popup