WordPress maintenance or security needs? Reach out!
TLDWP

Plugin: wpexpresspopup (Used by 6 domains)

Security snapshot

Across 6 wpexpresspopup WordPress sites indexed by TLDWP, compared to the all-WordPress average.

Grade A 0% Grade B 0% Grade C 0% Grade D 0% Grade F 100%
Fail the header check (F)100%vs 82.5% avg
Leak usernames17%vs 38.5% avg
Expose a sensitive file0%vs 1.8% avg
Use HTTPS100%vs 96.2% avg

What stands out

TLDWP currently associates 6 indexed WordPress sites with wpexpresspopup, equivalent to 0% of the current WordPress dataset.

The largest measured difference is username enumeration: 16.7% versus 38.5% overall (-21.8 percentage points).

Header-grade F is 100% vs 82.5% overall (+17.5 pp); HTTPS adoption is 100% vs 96.2% overall (+3.8 pp); Sensitive-file exposure is 0% vs 1.8% overall (-1.8 pp).

These are observational associations among sites where TLDWP detected wpexpresspopup, not evidence that the technology, provider, or domain attribute caused a security outcome. See the overall WordPress security baseline.

wpexpresspopup Premium / Custom

This plugin is not available on WordPress.org. It may be a premium plugin, a custom plugin, or a plugin from a third-party marketplace.

Domain Exposures Headers Last Checked
z*o*s*a*g*p*.nl (WP 6.4.10) F Sep 7, 2026
b*o*t*y*o*.com (WP 5.0.22) F Sep 6, 2026
b*o*t*a*o*.com (WP 5.0.22) F Sep 6, 2026
r*w*e*l*h.net F Aug 26, 2026
a*b*.it F Aug 20, 2026
f*o*b*l*s*v*g*s.com (WP 4.0.1) F Jul 29, 2026