
click-to-vote.me Security & Risk Analysis
wordpress.org/plugins/click-to-vote-meVery easy to use WordPress plugin to display click-to-vote.me polls.
Is click-to-vote.me Safe to Use in 2026?
Generally Safe
Score 85/100click-to-vote.me has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The click-to-vote-me v21.3.13 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL query handling by exclusively using prepared statements and has no recorded historical vulnerabilities, suggesting a generally stable development history. However, significant concerns arise from the lack of output escaping, where none of the identified output points are properly escaped. Additionally, the presence of unsanitized paths in taint analysis, even if not categorized as critical or high severity, indicates potential for unintended behavior or manipulation if user-supplied data is involved.
While the attack surface is small and appears to lack direct entry points without authentication or permission checks, the critical finding of unsanitized paths in taint analysis, coupled with the complete absence of output escaping, presents a notable risk. This suggests that data processed by the plugin might not be adequately validated or sanitized before being displayed, potentially leading to cross-site scripting (XSS) vulnerabilities if the plugin handles user-supplied input or dynamically generated content that is then rendered without proper sanitization. The lack of nonce checks and capability checks, while not directly flagged as problematic in this specific analysis, further contributes to a less robust security framework.
Key Concerns
- No output escaping implemented
- Taint analysis shows unsanitized paths
- No nonce checks
- No capability checks
click-to-vote.me Security Vulnerabilities
click-to-vote.me Code Analysis
Output Escaping
Data Flow Analysis
click-to-vote.me Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
click-to-vote.me Maintenance & Trust
Maintenance Signals
Community Trust
click-to-vote.me Alternatives
WP Video Lightbox
wp-video-lightbox
Very easy to use WordPress lightbox plugin to display YouTube and Vimeo videos in an elegant lightbox overlay.
MetaSlider Lightbox – Modals & Lightboxes – Image, Gallery, Video, Slideshow Lightbox
ml-slider-lightbox
MetaSlider Lightbox is the lightbox and modal plugin for WordPress. Build a lightbox for images, galleries, video, slideshows and more.
Video PopUp
video-popup
The ultimate Video Popup plugin for WordPress. Create unlimited and responsive popups for YouTube, Vimeo, MP4 & WebM videos on click or On-Page Load.
ARI Fancy Lightbox – Popup for WordPress
ari-fancy-lightbox
Lightbox for WordPress with social and viral features. Show photos, gallery, PDF, videos, WooCommerce images, inline content, Google Maps links.
WP Video Popup – WordPress Video Lightbox for YouTube, Rumble & Vimeo
responsive-youtube-vimeo-popup
WP Video Popup lets you add a responsive YouTube, Rumble or Vimeo video lightbox to any page, post or custom post type of your website.
click-to-vote.me Developer Profile
1 plugin · 10 total installs
How We Detect click-to-vote.me
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
click-to-vote-me/click-to-vote.php?ver=21.3.13HTML / DOM Fingerprints
<iframe width= height= src= frameborder='0'></iframe>