
BugHerd Security & Risk Analysis
wordpress.org/plugins/bugherdClient feedback on your WordPress site made ridiculously easy. No code changes or client logins. Syncs to Jira, Asana, ClickUp and more.
Is BugHerd Safe to Use in 2026?
Generally Safe
Score 100/100BugHerd has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of Bugherd v1.0.14 reveals a generally strong security posture with no identified dangerous functions, SQL injection vulnerabilities, or file operations. The absence of external HTTP requests and bundled libraries is also a positive sign. However, the analysis does highlight some areas for concern. The low percentage of properly escaped output (78%) suggests a potential for cross-site scripting (XSS) vulnerabilities, though the absence of known CVEs and taint analysis findings currently mitigates this risk. Furthermore, the complete lack of nonce checks and capability checks across all identified entry points, while currently presenting a zero attack surface, indicates a reliance on other security layers or a potential oversight in security implementation that could become a weakness if new entry points are introduced or if existing ones are exposed differently.
The plugin's vulnerability history is exceptionally clean, with no recorded CVEs. This, combined with the absence of critical or high severity taint flows, suggests a history of secure development practices or effective patching. While the lack of explicit capability checks is a noted weakness, the overall lack of identified vulnerabilities and the absence of critical code signals indicate that the plugin is likely safe to use in its current version. The primary recommendation would be to investigate and improve output escaping to reach 100% to proactively address potential XSS risks.
Key Concerns
- Low percentage of properly escaped output
- No nonce checks across entry points
- No capability checks across entry points
BugHerd Security Vulnerabilities
BugHerd Release Timeline
BugHerd Code Analysis
Output Escaping
BugHerd Attack Surface
WordPress Hooks 4
Maintenance & Trust
BugHerd Maintenance & Trust
Maintenance Signals
Community Trust
BugHerd Alternatives
Marker.io – Visual Website Feedback
marker-io
Collect visual website feedback from colleagues and clients on your WordPress site.
Feedbucket – Website Feedback Tool
feedbucket
Enable your clients and team members to submit feedback using screenshot and recordings on your WordPress site.
Simple Commenter – Website Feedback tool
simple-commenter
The website feedback tool your clients will actually use. Collect visual feedback directly on your site—no training required.
Webvizio
webvizio
The Ultimate Visual Feedback, Collaboration & Productivity Tool for Web Professionals.
PageProofer
pageproofer
Allow developers, designers, clients and site visitors to easily leave feedback directly on your website.
BugHerd Developer Profile
1 plugin · 3K total installs
How We Detect BugHerd
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
https://www.bugherd.com/sidebarv2.js