
Better WordPress Polldaddy Polls Security & Risk Analysis
wordpress.org/plugins/bwp-polldaddyHelps you add Polldaddy Polls to your WordPress website easily.
Is Better WordPress Polldaddy Polls Safe to Use in 2026?
Generally Safe
Score 85/100Better WordPress Polldaddy Polls has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The bwp-polldaddy plugin version 1.1.0 exhibits a mixed security posture. On the positive side, it demonstrates a lack of known historical vulnerabilities and a strong adherence to secure coding practices regarding SQL queries, utilizing prepared statements exclusively. Furthermore, the plugin shows a diligent use of nonces and capability checks on its limited entry points, suggesting an effort to control access. However, the static analysis reveals significant concerns. The presence of the `create_function` dangerous function is a red flag, as it can be a source of code injection vulnerabilities. The taint analysis indicates that all analyzed flows involve unsanitized paths, raising potential risks for data leakage or manipulation if these paths are reachable by user input. Additionally, a low percentage of output escaping (29%) is a critical weakness, making the plugin highly susceptible to Cross-Site Scripting (XSS) attacks across numerous output points. The external HTTP request, while singular, warrants scrutiny for potential vulnerabilities if not handled securely. The absence of direct attack surface entry points (AJAX, REST API, shortcodes) is commendable, but the presence of cron events and the aforementioned coding issues create latent risks. The plugin's vulnerability history being clean is encouraging, but the code signals and taint analysis point to inherent weaknesses that could be exploited. In conclusion, while the plugin avoids known vulnerabilities and manages its direct attack surface well, the use of dangerous functions, unsanitized taint flows, and poor output escaping create substantial risks that need immediate attention.
Key Concerns
- Dangerous function create_function used
- Unsanitized paths in taint flows
- Low percentage of output escaping
- External HTTP request without clear context
Better WordPress Polldaddy Polls Security Vulnerabilities
Better WordPress Polldaddy Polls Release Timeline
Better WordPress Polldaddy Polls Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Better WordPress Polldaddy Polls Attack Surface
WordPress Hooks 18
Scheduled Events 2
Maintenance & Trust
Better WordPress Polldaddy Polls Maintenance & Trust
Maintenance Signals
Community Trust
Better WordPress Polldaddy Polls Alternatives
Crowdsignal Forms
crowdsignal-forms
The Crowdsignal Forms plugin allows you to create and manage polls right from within the block editor.
Crowdsignal Dashboard – Polls, Surveys & more
polldaddy
Manage your Crowdsignal polls, surveys, quizzes, and ratings directly from the WordPress dashboard.
WP-Polls
wp-polls
Adds an AJAX poll system to your WordPress blog. You can also easily add a poll into your WordPress's blog post/page.
YOP Poll
yop-poll
Use a full option polling solution to get the answers you need. YOP Poll is the perfect, easy to use poll plugin for your WordPress site.
Democracy Poll
democracy-poll
WordPress polls plugin with multiple-choice, custom answers, cache compatibility, widgets, and shortcodes.
Better WordPress Polldaddy Polls Developer Profile
5 plugins · 9K total installs
How We Detect Better WordPress Polldaddy Polls
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bwp-polldaddy/css/bwp-polldaddy-frontend.css/wp-content/plugins/bwp-polldaddy/js/bwp-polldaddy-frontend.jsbwp-polldaddy/css/bwp-polldaddy-frontend.css?ver=bwp-polldaddy/js/bwp-polldaddy-frontend.js?ver=