Description
FireBox displays popups, bars, and onsite campaigns that react to WooCommerce data, reading cart content, total value, and purchase history to decide which offer to show each visitor. With built-in capture forms, a free shipping progress bar, and revenue attribution per campaign, it ties every popup to real revenue in WooCommerce and Easy Digital Downloads stores, showing which campaigns actually generate sales and not just views.
Key Features of FireBox
- Cart data segmentation
Triggers campaigns based on cart items, total value, and the visitor’s previous purchases. - Revenue attribution
Tracks revenue per view and per conversion in WooCommerce and Easy Digital Downloads. - Free shipping progress bar
Shows in real time how much more the customer needs to reach the free shipping threshold. - Upsell and cross-sell campaigns
Recommends related products, best sellers, and recently viewed items on the product page. - Capture forms with syncing
Sends every signup straight to the email service, no CSV exports needed.
Benefits of FireBox
- Fewer abandoned carts
Reminders of what’s left in the cart recover sales before the visitor leaves. - Higher average order value
Freebie offers and recommendations raise the amount spent per order. - Revenue-based decisions
Cut campaigns that only generate views and keep the ones that sell. - Growing contact list
Coupons, giveaways, and free materials convert anonymous visits into subscribers.
Who Is FireBox For?
- Anyone selling physical products on WooCommerce and losing orders to abandoned carts.
- Anyone distributing digital products through Easy Digital Downloads who wants to measure each campaign’s revenue.
- Aimed at those who need to grow their email list with coupons, giveaways, and free materials.
- Anyone already running ads for their store who wants to raise average order value with free shipping and freebie offers.
How to Download FireBox
FireBox is available for download here on Ultrapack. The step-by-step for installing this file is in the How to install tab, next to the description. Once activated, the campaigns and revenue reports appear in the WordPress admin dashboard.
Among popup builders, FireBox’s edge is using the store’s own data as the display criteria: someone with a specific product in their cart sees one offer, someone close to the free shipping threshold sees another. For anyone selling online who’s tired of measuring campaigns by impressions, revenue attribution shows in numbers which campaigns actually pay for themselves.
Frequently asked questions
Is FireBox – WordPress Popup Builder Plugin GPL-licensed?
Yes. FireBox – WordPress Popup Builder Plugin is distributed under the GPL (GNU General Public License). You may legally use, modify and redistribute it on as many sites as you want.
Can I use FireBox – WordPress Popup Builder Plugin on multiple sites?
Yes. You can install FireBox – WordPress Popup Builder Plugin on as many sites as you want. Only automatic updates through Ultrapack Auto Updater have a limit: from 3 to 80 sites, depending on the plan.
How much does FireBox – WordPress Popup Builder Plugin cost at Ultrapack?
FireBox – WordPress Popup Builder Plugin costs US$2.99 as a single purchase, and it is also included in the subscription plans starting at US$12/mo (VIP I).
Does FireBox – WordPress Popup Builder Plugin include updates?
Yes. The current version of FireBox – WordPress Popup Builder Plugin is 3.1.13, published at Ultrapack on Sep 7, 2026. Subscribers update straight from the WordPress dashboard with UAU (Ultrapack Auto Updater).
Is FireBox – WordPress Popup Builder Plugin scanned before publication?
Yes. Every version of FireBox – WordPress Popup Builder Plugin goes through a malware scan (ClamAV and YARA rules, at UltraHub) before it is published.
What are the requirements for the plugin FireBox – WordPress Popup Builder Plugin?
Requires WordPress 6.3 or higher and PHP 7.0 or higher. Tested up to WordPress 7.1.
What changed in this version
Version 3.1.13 Sep 7, 2026
- Improved security across the plugin, including how campaigns are searched, previewed and tracked, how form submissions and integrations are handled, and how visitor information is read.
- Improved: the {user.*} Smart Tag now only returns profile details such as name and email.
- Improved: stored integration credentials (MailChimp, Brevo, Klaviyo and others) get an extra layer of protection. Existing connections keep working.
- Improved: visitor cookies now work correctly on sites served over plain HTTP.
- Improved: IP and Geolocation conditions now detect a reverse proxy on your own network automatically. If your site sits behind a CDN that does not pass the visitor's address through to WordPress, the new fpframework/trusted_proxies filter lets you tell FireBox about it.
- Improved: the Cloudflare Turnstile and hCaptcha setup notice in the campaign editor now also appears when only the secret key is missing.
- Fixed: the Brevo integration failed to load your contact lists.
Version 3.1.12 Aug 28, 2026
- Fixed an issue in the free version where a campaign using Custom JavaScript could cause an error on the front end.
Version 3.1.11 Aug 26, 2026
- Improved compatibility with WP Rocket: FireBox now automatically excludes its files from Delay JavaScript Execution, minification, and Remove Unused CSS, so campaigns keep working without adding manual exclusions in WP Rocket's settings.
- Improved security: custom PHP in display conditions and PHP Scripts now runs only for campaigns whose author holds a dedicated "run PHP" permission. Administrators have it by default; other roles cannot run PHP unless you grant them the permission deliberately.
- Improved security: custom JavaScript and custom CSS on a campaign now run only for campaigns whose author is allowed to add code. Administrators can by default; other roles cannot add custom code unless you grant them the permission deliberately. Custom CSS is also cleaned so it can't be used to inject anything other than styles.
- Improved security: turning a campaign on or off from the campaigns list now checks that you have permission to edit that specific campaign, and only ever changes FireBox campaigns.
- Improved security: values taken from the current page address and the referring page now have any code removed before they appear inside a campaign, so a crafted link can't inject content into your campaigns.
- Improved security: duplicating a campaign now checks you have permission to edit it, and the copy belongs to whoever created it.
Version 3.1.10 Aug 18, 2026
- WordPress 7.1 compatibility.
- Added: a limit on how many times the same visitor can submit a form each minute, so a single visitor can't spam your submissions list.
- Improved Multisite support: FireBox now sets itself up on every site of a network, including sites added later, so campaigns, analytics and permissions work without visiting each site first.
- Improved Multisite support: campaigns on different sites of a network no longer share cookies, so closing a campaign on one site can't hide a campaign on another.
- Improved Multisite support: removing FireBox from a network now clears each site's data according to that site's own "Keep data on uninstall" setting, and deleting a site removes its FireBox data with it.
- Improved: cookies now follow your site's WordPress cookie settings, so campaign frequency and analytics keep working on sites that share cookies between www and non-www addresses.
- Improved how integration credentials (MailChimp, Brevo, Klaviyo, and others) are stored.
- Improved the handling of imported campaigns so their content is cleaned up before it is saved.
- Improved how Rating field values are shown in the Submissions list.
- Improved: campaigns now use their own set of permissions, so you can give someone access to campaigns without giving them access to all your posts.
- Improved the accuracy of conversion and analytics tracking by ignoring invalid or duplicated data.
- Improved: connecting or disconnecting an integration now requires administrator access.
- Improved privacy: FireBox no longer tells WordPress.org about itself when WordPress checks for plugin updates.
- Improved the handling of the {fbExpr} expression feature.
- Improved the handling of redirects and messages shown after a form is submitted.
- Improved the delete and duplicate actions in the campaigns list.
- Improved: page speed for campaigns with custom JavaScript no longer hold up the rest of the page while FireBox loads. Custom code now runs right after your campaigns are ready.
- Improved: page speed when serving multiple FireBox campaigns on same page.
- Improved: page speed by loading only the animations your campaign uses, instead of the whole animation library. This cuts about 69KB from every page a campaign appears on.
- Fixed: page slide campaigns could appear full-height and outside their slide area on some sites.
- Fixed: an error that could occur while FireBox was updating itself.
Version 3.1.9 Jul 16, 2026
- Added: a new campaigns list with ability to sort, filter, and manage your campaigns in bulk.
- Improved security of visitor cookie handling on campaigns using a daily, weekly, or monthly display frequency.
- Improved security of Phone Number values shown in the Submissions list and in admin notification emails.
- Improved security of the {post.*} and {cookie.*} Smart Tags, which now strip HTML from their values, matching the {querystring.*} Smart Tag.
- Improved: Compatibility of YouTube shorts in the Video block.
- Improved: replaced PHP sessions with cookies on the front-end, restoring full-page caching compatibility and fixing the Site Health "active PHP session" warning and REST API loopback timeouts.
- Improved: cookies are now only set when a campaign actually needs them (e.g. Pageviews condition).
- Improved: the front-end script now loads deferred for faster page rendering.
- Improved: campaign and settings lookups are now cached on sites with a persistent object cache.
- Improved: WordPress 6.3 compatibility.
- Improved: campaign revenue now excludes refunded WooCommerce and Easy Digital Downloads orders, matching your shop's own analytics. Use the firebox/revenue_attribution/order_total filter to restore gross revenue.
- Fixed: MailChimp integration removed a subscriber's existing tags and interest groups even when "Replace Tags?" was turned off.
- Fixed: a campaign containing a Heading, Button, or Paragraph block set to a Google font could fail to render on the front-end in some saved or imported campaigns.
- Fixed: submitting a form with an optional Phone Number field, or editing a submission with malformed data, could trigger a PHP error.
- Fixed: exporting campaigns via a malformed request could trigger a PHP error before the security check.
- Fixed: corrected a build marker in the upgrade routine that could mis-package the Free, Basic, and Growth builds.
- Fixed: the Phone Number field appeared unstyled in the block editor due to missing stylesheet.
- Fixed: the Performance chart kept a Weekly or Monthly grouping selected after switching to a shorter timeframe that no longer supports it, now falls back to Daily automatically.
- Fixed: YouTube videos in the Video block failed to load in the block editor preview with "Error 153".
- Fixed: a {cookie.*} Smart Tag referencing a cookie that was not set could blank out the campaign's content.
- Removed: the mini onboarding appearing after the first install.
Release notes published by the developer.
How to install
Automatic updates: this item is updated by the Ultrapack Auto Updater. With it installed, the new version shows up in your dashboard like any other WordPress update (how to set it up).
- Download the file
firebox-pro.zip. - In the WordPress dashboard, go to Plugins > Add New > Upload Plugin.
- Select the file
firebox-pro.zipand click Install Now. - Click Activate.
Requirements: Requires WordPress 6.3 or higher and PHP 7.0 or higher. Tested up to WordPress 7.1.
Stuck on a step? Open a ticket telling us which one you stopped at.

UAU Ready