
Popup Builder & Opt-in Forms – Exit Intent, Coupon & Floating Bar Popups by YSLeadGen Security & Risk Analysis
wordpress.org/plugins/ysleadgenPopup builder for exit intent popups, coupon popups, floating bars, and opt-in forms to grow leads and increase conversions on WordPress sites.
Is Popup Builder & Opt-in Forms – Exit Intent, Coupon & Floating Bar Popups by YSLeadGen Safe to Use in 2026?
Generally Safe
Score 100/100Popup Builder & Opt-in Forms – Exit Intent, Coupon & Floating Bar Popups by YSLeadGen has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "ysleadgen" v1.1.6 plugin exhibits a generally strong security posture with excellent practices in SQL query preparation and output escaping, indicating developers are aware of common web vulnerabilities. The absence of known CVEs and bundled libraries further contributes positively. However, a significant concern arises from the 8 AJAX handlers that lack authentication checks. While the plugin has a large number of nonce and capability checks, these unprotected AJAX endpoints represent a direct attack vector that could be exploited if they handle user-supplied input without proper validation, potentially leading to unauthorized actions.
The taint analysis reveals 9 flows with unsanitized paths, all classified as high severity. This is a critical finding and suggests that user input is not being sufficiently cleaned before being used in sensitive operations. Coupled with the unprotected AJAX handlers, these unsanitized paths present a substantial risk of various vulnerabilities, including cross-site scripting (XSS) or path traversal, depending on how the unsanitized data is processed.
While the plugin's vulnerability history is clean, suggesting a good track record or recent development, the current static analysis findings of unprotected AJAX endpoints and high-severity unsanitized flows cannot be ignored. The strengths lie in the robust implementation of prepared statements and output escaping. The weaknesses, however, are significant and require immediate attention: the unprotected entry points and the identified taint flows pose a clear and present danger to the security of a WordPress site using this plugin.
Key Concerns
- Unprotected AJAX handlers
- High severity unsanitized taint flows
Popup Builder & Opt-in Forms – Exit Intent, Coupon & Floating Bar Popups by YSLeadGen Security Vulnerabilities
Popup Builder & Opt-in Forms – Exit Intent, Coupon & Floating Bar Popups by YSLeadGen Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Popup Builder & Opt-in Forms – Exit Intent, Coupon & Floating Bar Popups by YSLeadGen Attack Surface
AJAX Handlers 59
REST API Routes 1
Shortcodes 2
WordPress Hooks 20
Maintenance & Trust
Popup Builder & Opt-in Forms – Exit Intent, Coupon & Floating Bar Popups by YSLeadGen Maintenance & Trust
Maintenance Signals
Community Trust
Popup Builder & Opt-in Forms – Exit Intent, Coupon & Floating Bar Popups by YSLeadGen Alternatives
Popup Builder – Create highly converting, mobile friendly marketing popups.
popup-builder
Increase Sales, Lead Generation, Conversion rates and receive good Call to Action rates with smart WordPress popup plugin.
Getsitecontrol — Email Marketing Plugin | Popup Maker, Automations & Newsletters
getsitecontrol
Complete email marketing toolset with a powerful popup builder on board. Generate leads with email opt-in forms, send professional newsletters, build …
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More
wpforms-lite
The best WordPress contact form plugin. Drag & Drop form builder to create beautiful contact forms, payment forms, & other custom forms.
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder
fluentform
Get a fast contact form plugin. Create advanced forms using drag and drop form builder with all smart features.
MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor
metform
The most popular Elementor forms builder to create WordPress forms like contact forms, booking forms, feedback form, survey forms, application forms a …
Popup Builder & Opt-in Forms – Exit Intent, Coupon & Floating Bar Popups by YSLeadGen Developer Profile
1 plugin · 10 total installs
How We Detect Popup Builder & Opt-in Forms – Exit Intent, Coupon & Floating Bar Popups by YSLeadGen
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ysleadgen/admin-ui/dist/bundle.js/wp-content/plugins/ysleadgen/admin-ui/dist/output.css/wp-content/plugins/ysleadgen/admin-ui/dist/bundle.jsysleadgen/admin-ui/dist/bundle.js?ver=ysleadgen/admin-ui/dist/output.css?ver=HTML / DOM Fingerprints
ysleadgen-admindata-page="dashboard"ysLeadGenData/wp-json/ysleadgen/v1/