
Atarim – Visual Feedback, Review & AI Collaboration Security & Risk Analysis
wordpress.org/plugins/atarim-visual-collaborationMake collecting feedback on WordPress sites MUCH faster and easier, with the visual collaboration tool used on over 120,000 websites worldwide.
Is Atarim – Visual Feedback, Review & AI Collaboration Safe to Use in 2026?
Mostly Safe
Score 76/100Atarim – Visual Feedback, Review & AI Collaboration is generally safe to use. 18 past CVEs were resolved. Keep it updated.
The 'atarim-visual-collaboration' plugin v4.3.4 presents a mixed security posture. While it demonstrates good practices in SQL query handling and a majority of output escaping, significant concerns are raised by its attack surface and vulnerability history. The presence of two AJAX handlers without authentication checks is a critical vulnerability, directly exposing potential attack vectors. This, combined with four taint flows involving unsanitized paths, even if not rated critical or high, suggests a concerning lack of input validation and sanitization in key areas.
The plugin's historical vulnerability data is alarming, with 18 known CVEs, including 3 critical and 3 high. The common vulnerability types such as 'Exposure of Sensitive Information', 'Unrestricted Upload', 'Incorrect Privilege Assignment', and 'Missing Authorization' indicate a recurring pattern of fundamental security flaws. The fact that all previous vulnerabilities are currently patched is a positive sign, but the sheer volume and severity of past issues, coupled with the current code analysis findings, point to a history of insecure development practices. The most recent vulnerability being in 2026 also suggests a potential for future discoveries, or perhaps a typo in the data provided.
In conclusion, while the plugin shows some positive security attributes like prepared SQL statements and partial output escaping, the identified unprotected AJAX handlers and the extensive, severe vulnerability history far outweigh these strengths. The plugin should be considered high risk until further improvements are made to its authorization mechanisms and input sanitization processes.
Key Concerns
- Unprotected AJAX handlers
- Taint flows with unsanitized paths
- Total known CVEs (18)
- Critical severity CVEs (3)
- High severity CVEs (3)
- Missing authorization vulnerability type history
- Exposure of sensitive information vuln type history
- Improper neutralization of input (XSS) vuln type history
Atarim – Visual Feedback, Review & AI Collaboration Security Vulnerabilities
CVEs by Year
Severity Breakdown
18 total CVEs
Atarim <= 4.2.1 - Missing Authorization
Atarim <= 4.3.1 - Missing Authorization
Atarim <= 4.2.1 - Unauthenticated Information Exposure
Atarim <= 4.2.1 - Unauthenticated Arbitrary File Upload
Atarim <= 4.2.1 - Unauthenticated Information Exposure
Atarim <= 4.2.1 - Unauthenticated Privilege Escalation
Atarim <= 4.1.0 - Reflected Cross-Site Scripting
Atarim <= 4.0.8 - Unauthenticated Stored Cross-Site Scripting
Visual Website Collaboration, Feedback & Project Management – Atarim <= 4.0.9 - Missing Authorization to Authenticated (Subscriber+) Project Page/File Deletion
Atarim <= 4.0.1 - Missing Authorization via remove_feedbacktool_notice()
Visual Website Collaboration, Feedback & Project Management – Atarim <= 4.0.2 - Missing Authorization to Authenticated (Subscriber+) Settings Update
Atarim <= 4.0 - Missing Authorization
Atarim <= 3.31 - Authenticated (Administrator+) Stored Cross-Site Scripting
Visual Website Collaboration, Feedback & Project Management – Atarim <= 3.30 - Unauthenticated Stored Cross-Site Scripting
Visual Website Collaboration, Feedback & Project Management – Atarim <= 3.22.6 - Hardcoded Credentials
Atarim <= 3.12 - Unauthenticated Cross-Site Scripting
Atarim <= 3.9.3 - Reflected Cross-Site Scripting
Atarim - Client Interface <= 3.9.1 - Missing Authorization via AJAX actions
Atarim – Visual Feedback, Review & AI Collaboration Code Analysis
Output Escaping
Data Flow Analysis
Atarim – Visual Feedback, Review & AI Collaboration Attack Surface
AJAX Handlers 4
WordPress Hooks 17
Maintenance & Trust
Atarim – Visual Feedback, Review & AI Collaboration Maintenance & Trust
Maintenance Signals
Community Trust
Atarim – Visual Feedback, Review & AI Collaboration Alternatives
Supernifty Bublz
supernifty-bublz
Click anything on your site. Pin a task to it. Track it on a kanban board. Bug reporting and feedback built into WordPress.
Webvizio
webvizio
The Ultimate Visual Feedback, Collaboration & Productivity Tool for Web Professionals.
Simple Commenter – Website Feedback tool
simple-commenter
The website feedback tool your clients will actually use. Collect visual feedback directly on your site—no training required.
SureFeedback Cloud
surefeedback-cloud
SureFeedback Cloud helps teams collect visual feedback on WordPress sites and designs. Fast client sharing, zero hosting needed.
Annotatr – Bug Reporting, Bug Tracking, Kanban Board and Project Management
annotatr
Visual feedback and bug tracking for WordPress. Capture, assign, and fix issues without leaving your site — no more chasing reports.
Atarim – Visual Feedback, Review & AI Collaboration Developer Profile
1 plugin · 1K total installs
How We Detect Atarim – Visual Feedback, Review & AI Collaboration
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/atarim-visual-collaboration/assets/css/settings.css/wp-content/plugins/atarim-visual-collaboration/assets/build/index.js/wp-content/plugins/atarim-visual-collaboration/assets/js/admin.jsassets/build/index.jsassets/js/admin.jsatarim-visual-collaboration/assets/css/settings.css?ver=atarim-visual-collaboration/assets/build/index.js?ver=atarim-visual-collaboration/assets/js/admin.js?ver=HTML / DOM Fingerprints
avc-settings-rootid="avc-settings-root"AVCF_PLUGIN_URLAVCF_VERSIONAVCF_HOME_URLAVCF_SITE_URL