
Zotabox – 20+ Promotional Sales tools to boost your subscribers and sales Security & Risk Analysis
wordpress.org/plugins/zotaboxBoost your subscribers and sales with 20+ popular on-site marketing tools: Email List Builder, Social Coupon, Countdown Timer, Mailchimp Forms, Popups
Is Zotabox – 20+ Promotional Sales tools to boost your subscribers and sales Safe to Use in 2026?
Generally Safe
Score 100/100Zotabox – 20+ Promotional Sales tools to boost your subscribers and sales has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "zotabox" v1.9.2 exhibits a strong security posture based on the provided static analysis. It demonstrates good practices by having no identified dangerous functions, all SQL queries using prepared statements, and all output properly escaped. The absence of file operations and external HTTP requests further reduces potential attack vectors. Importantly, the presence of nonce checks on its AJAX handlers is a positive indicator of security awareness, even though capability checks are not explicitly noted on these entry points.
The taint analysis shows zero flows with unsanitized paths, indicating that data processed by the plugin is not being mishandled in a way that could lead to common vulnerabilities like path traversal. The lack of any recorded historical vulnerabilities (CVEs) is also a significant strength, suggesting a history of secure development or diligent patching.
However, the analysis does highlight a potential area for improvement. While the two identified AJAX handlers have nonce checks, the absence of explicit capability checks on these entry points means that any authenticated user could potentially trigger these handlers. While not an immediate critical risk given the other positive signals, this could be an avenue for exploitation if the AJAX actions themselves have sensitive implications or can be used in conjunction with other vulnerabilities.
Key Concerns
- AJAX handlers lack capability checks
Zotabox – 20+ Promotional Sales tools to boost your subscribers and sales Security Vulnerabilities
Zotabox – 20+ Promotional Sales tools to boost your subscribers and sales Code Analysis
Output Escaping
Data Flow Analysis
Zotabox – 20+ Promotional Sales tools to boost your subscribers and sales Attack Surface
AJAX Handlers 2
WordPress Hooks 4
Maintenance & Trust
Zotabox – 20+ Promotional Sales tools to boost your subscribers and sales Maintenance & Trust
Maintenance Signals
Community Trust
Zotabox – 20+ Promotional Sales tools to boost your subscribers and sales Alternatives
WPB Popup for Contact Form 7 – Showing The Contact Form 7 Popup on Button Click – CF7 Popup
wpb-popup-for-contact-form-7
Popup for Contact Form 7 can boost your sales, leads, and conversions. It only takes a few clicks to setup a Contact Form 7 Popup on Button Click.
Popups – Submission Messages For Contact Form 7
cf7-popups
Display contact form 7 default messages in stylish popup as user submits the form.
Popup for CF7 with Sweet Alert
cf7-sweet-alert-popup
Popup for CF7 with Sweet Alert
Slick Popup: Contact Form 7 Popup Plugin
slick-popup
A lightweight plugin that converts a Contact Form 7 form into a customizable pop-up form which is slick, beautiful and responsive to different screen …
Coupon X – Discount Popups & Promo Codes Pop Ups for WooCommerce
coupon-x-discount-pop-up
Boost sales with engaging discount pop ups, coupon widgets, promo code pop up & coupon codes! Generate unique promo codes or use existing codes 🛒
Zotabox – 20+ Promotional Sales tools to boost your subscribers and sales Developer Profile
12 plugins · 4K total installs
How We Detect Zotabox – 20+ Promotional Sales tools to boost your subscribers and sales
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/zotabox/assets/css/style.css/wp-content/plugins/zotabox/assets/js/main.js/wp-content/plugins/zotabox/assets/js/main.jsHTML / DOM Fingerprints
ztb-register-formztb-submit-buttonztb-wrapperztb-logoztb-code-wrapperztb-titleaccount-inputztb-buttonzb-pluginZBT_WP_ADMIN_URLZTB_BASE_URL