Celebrity Polls Security & Risk Analysis

wordpress.org/plugins/celebrity-polls

We have developed a plugin that allows you, the Admin of your blog, to

10 active installs v1.1.0 beta PHP + WP 2.8.0+ Updated May 8, 2012
celebrityfacebooksinger22socialsocial-network
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Celebrity Polls Safe to Use in 2026?

Generally Safe

Score 85/100

Celebrity Polls has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

The celebrity-polls plugin v1.1.0 beta presents a mixed security posture. On the positive side, the plugin demonstrates good practices regarding database interactions, with all SQL queries utilizing prepared statements. Furthermore, it reports zero known CVEs, indicating a historical lack of publicly disclosed vulnerabilities. This suggests a level of diligence in maintaining the codebase. However, significant concerns arise from the static analysis. The lack of any output escaping is a critical weakness, potentially exposing users to Cross-Site Scripting (XSS) vulnerabilities if any of the analyzed outputs are user-controlled. The presence of two flows with unsanitized paths, even without a critical severity rating, warrants attention as it suggests potential for path traversal or insecure file handling, especially considering the three file operations. The absence of nonce and capability checks, alongside an apparent zero attack surface for entry points, is unusual and could either mean the plugin is very basic or that the analysis tools missed potential interaction points. The lack of these fundamental WordPress security checks, coupled with the unsanitized paths and unescaped output, creates a risk profile that cannot be ignored despite the absence of known CVEs.

Key Concerns

  • 0% output escaping found
  • 2 flows with unsanitized paths
  • 0 nonce checks
  • 0 capability checks
  • 3 file operations with no explicit security checks evident
Vulnerabilities
None known

Celebrity Polls Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Celebrity Polls Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
3
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped3 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
s22survey_write_managemenu (adminmenu.php:4)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Celebrity Polls Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionwp_enqueue_scriptss22survey.php:25
filterfavorite_actionss22survey.php:64
actionadmin_menus22survey.php:68
Maintenance & Trust

Celebrity Polls Maintenance & Trust

Maintenance Signals

WordPress version tested3.3.2
Last updatedMay 8, 2012
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Celebrity Polls Developer Profile

infectionrank.org

2 plugins · 50 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Celebrity Polls

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/celebrity-polls/s22survey.css

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Celebrity Polls