
Democracy Poll Security & Risk Analysis
wordpress.org/plugins/democracy-pollWordPress polls plugin with multiple-choice, custom answers, cache compatibility, widgets, and shortcodes.
Is Democracy Poll Safe to Use in 2026?
Mostly Safe
Score 75/100Democracy Poll is generally safe to use. 3 past CVEs were resolved. Keep it updated.
The democracy-poll plugin v6.1.1 presents a mixed security posture. While it demonstrates some good practices, such as the use of nonces and capability checks in some areas and a moderate percentage of SQL queries using prepared statements, significant concerns remain. The presence of two AJAX handlers without authorization checks creates a direct attack vector for unauthenticated users. The taint analysis revealing three high-severity flows with unsanitized paths is particularly worrying, suggesting potential for code injection or data leakage if these flows are exploitable.
The plugin's vulnerability history is a strong indicator of ongoing security issues, with three known CVEs, one of which is currently unpatched. The common types of vulnerabilities (Missing Authorization, CSRF, XSS) align with the findings in the static analysis, particularly the unauthenticated AJAX handlers and the taint analysis results. The recency of the last vulnerability (April 2024) suggests that these issues may not be historical and could still be present or easily reintroduced. While the plugin has some strengths, the combination of unprotected entry points, critical taint flows, and a history of unpatched vulnerabilities necessitates a cautious approach.
Key Concerns
- Unprotected AJAX handlers
- High severity unsanitized taint flows
- Unpatched high severity CVE
- SQL queries using prepared statements < 75%
- Output escaping < 50%
- Vulnerability history: 3 known CVEs
Democracy Poll Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Democracy Poll <= 6.0.3 - Missing Authorization
Democracy Poll <= 5.3.6 - Cross-Site Request Forgery
Democracy Poll < 5.4 - Cross-Site Scripting
Democracy Poll Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Democracy Poll Attack Surface
AJAX Handlers 2
Shortcodes 2
WordPress Hooks 20
Maintenance & Trust
Democracy Poll Maintenance & Trust
Maintenance Signals
Community Trust
Democracy Poll Alternatives
Crowdsignal Dashboard – Polls, Surveys & more
polldaddy
Manage your Crowdsignal polls, surveys, quizzes, and ratings directly from the WordPress dashboard.
Polls CP
cp-polls
Create classic polls and advanced polls with dependant questions. Voting / survey system.
Poll And Survey plugin
poll-and-survey
This poll and survey plugin allows you to run any customized survey, poll or vote in your website. It could help you to get visitors/users openions ea …
Crowdsignal Forms
crowdsignal-forms
The Crowdsignal Forms plugin allows you to create and manage polls right from within the block editor.
WP-Polls
wp-polls
Adds an AJAX poll system to your WordPress blog. You can also easily add a poll into your WordPress's blog post/page.
Democracy Poll Developer Profile
5 plugins · 22K total installs
How We Detect Democracy Poll
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/democracy-poll/admin/css/jquery-ui.css/wp-content/plugins/democracy-poll/js/admin.js/wp-content/plugins/democracy-poll/admin/css/admin.css/wp-content/plugins/democracy-poll/js/admin.jsdemocracy-poll/admin/css/jquery-ui.css?ver=democracy-poll/js/admin.js?ver=democracy-poll/admin/css/admin.css?ver=HTML / DOM Fingerprints
democracy-poll-wrapdata-democr-poll-iddata-democr-answer-iddata-democr-admin-ajaxurlDemocracyPolldemocracy_poll_admin_ajax<div class="democr-poll-results-count"><div class="democr-poll-answer-wrap"><div class="democr-poll-wrap">