Zotabox – 20+ Promotional Sales tools to boost your subscribers and sales Security & Risk Analysis

wordpress.org/plugins/zotabox

Boost your subscribers and sales with 20+ popular on-site marketing tools: Email List Builder, Social Coupon, Countdown Timer, Mailchimp Forms, Popups

500 active installs v1.9.2 PHP 7.0+ WP 3.0.1+ Updated Apr 14, 2025
addthisaweber-formcontact-formcouponpopup
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Zotabox – 20+ Promotional Sales tools to boost your subscribers and sales Safe to Use in 2026?

Generally Safe

Score 100/100

Zotabox – 20+ Promotional Sales tools to boost your subscribers and sales has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The plugin "zotabox" v1.9.2 exhibits a strong security posture based on the provided static analysis. It demonstrates good practices by having no identified dangerous functions, all SQL queries using prepared statements, and all output properly escaped. The absence of file operations and external HTTP requests further reduces potential attack vectors. Importantly, the presence of nonce checks on its AJAX handlers is a positive indicator of security awareness, even though capability checks are not explicitly noted on these entry points.

The taint analysis shows zero flows with unsanitized paths, indicating that data processed by the plugin is not being mishandled in a way that could lead to common vulnerabilities like path traversal. The lack of any recorded historical vulnerabilities (CVEs) is also a significant strength, suggesting a history of secure development or diligent patching.

However, the analysis does highlight a potential area for improvement. While the two identified AJAX handlers have nonce checks, the absence of explicit capability checks on these entry points means that any authenticated user could potentially trigger these handlers. While not an immediate critical risk given the other positive signals, this could be an avenue for exploitation if the AJAX actions themselves have sensitive implications or can be used in conjunction with other vulnerabilities.

Key Concerns

  • AJAX handlers lack capability checks
Vulnerabilities
None known

Zotabox – 20+ Promotional Sales tools to boost your subscribers and sales Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Zotabox – 20+ Promotional Sales tools to boost your subscribers and sales Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
6 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped6 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
update_zb_zbapp_code (zotabox.php:180)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Zotabox – 20+ Promotional Sales tools to boost your subscribers and sales Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_update_zb_zbapp_codezotabox.php:177
noprivwp_ajax_update_zb_zbapp_codezotabox.php:178
WordPress Hooks 4
actionadmin_initzotabox.php:15
actionadmin_noticeszotabox.php:46
actionadmin_menuzotabox.php:81
actionwp_headzotabox.php:174
Maintenance & Trust

Zotabox – 20+ Promotional Sales tools to boost your subscribers and sales Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedApr 14, 2025
PHP min version7.0
Downloads54K

Community Trust

Rating94/100
Number of ratings41
Active installs500
Developer Profile

Zotabox – 20+ Promotional Sales tools to boost your subscribers and sales Developer Profile

Zotabox

12 plugins · 4K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
1712 days
View full developer profile
Detection Fingerprints

How We Detect Zotabox – 20+ Promotional Sales tools to boost your subscribers and sales

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/zotabox/assets/css/style.css/wp-content/plugins/zotabox/assets/js/main.js
Script Paths
/wp-content/plugins/zotabox/assets/js/main.js

HTML / DOM Fingerprints

CSS Classes
ztb-register-formztb-submit-buttonztb-wrapperztb-logoztb-code-wrapperztb-titleaccount-inputztb-button
Data Attributes
zb-plugin
JS Globals
ZBT_WP_ADMIN_URLZTB_BASE_URL
FAQ

Frequently Asked Questions about Zotabox – 20+ Promotional Sales tools to boost your subscribers and sales