
Document Feedback Security & Risk Analysis
wordpress.org/plugins/document-feedbackClose the loop — get feedback from readers on the documentation you write.
Is Document Feedback Safe to Use in 2026?
Generally Safe
Score 85/100Document Feedback has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "document-feedback" plugin version 1.3 exhibits a generally strong security posture based on the provided static analysis. It demonstrates excellent practices by having no identified dangerous functions, all SQL queries utilizing prepared statements, and a very high percentage of properly escaped output. The plugin also correctly implements nonce checks for its single AJAX handler, and importantly, has no known vulnerabilities recorded in its history. This indicates a mature and well-maintained plugin with a focus on secure coding principles.
However, there is a notable absence of capability checks for its AJAX handler. While a nonce check is present, this handler could potentially be accessed by any authenticated user, regardless of their role or permissions. The lack of taint analysis results and a small attack surface could be misleading; it's possible that more complex or subtle vulnerabilities exist but were not detected by the analysis tools used. Nonetheless, the current evidence points to a low-risk plugin, with the primary area for improvement being the addition of appropriate capability checks to further restrict access to its functionality.
In conclusion, this plugin appears to be a secure option for users. Its strengths lie in its clean code regarding SQL, output sanitization, and the absence of historical vulnerabilities. The sole significant concern is the missing capability check on the AJAX endpoint, which is a minor but important security hardening step that should be addressed.
Key Concerns
- Missing capability checks on AJAX handler
Document Feedback Security Vulnerabilities
Document Feedback Code Analysis
Output Escaping
Document Feedback Attack Surface
AJAX Handlers 1
WordPress Hooks 10
Maintenance & Trust
Document Feedback Maintenance & Trust
Maintenance Signals
Community Trust
Document Feedback Alternatives
UserFeedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds
userfeedback-lite
Ultimate user feedback plugin to ask questions, surveys, polls, from your website in seconds
kk Star Ratings – Rate Post & Collect User Feedbacks
kk-star-ratings
kk Star Ratings allows blog visitors to involve and interact more effectively with your website by rating posts.
WP ULike – Like & Dislike Buttons for Engagement and Feedback
wp-ulike
Voting buttons that let your visitors give instant feedback. See what your audience loves with no registration, no friction, just one click.
BetterDocs – Knowledge Base Docs & FAQ Solution for Elementor & Block Editor
betterdocs
A full-featured documentation plugin including AI writing assistance to create knowledge bases, docs, FAQs, wikis, and more with easy drag & drop UI.
Contact Form & SMTP Plugin for WordPress by PirateForms
pirate-forms
A simple and effective WordPress contact form & SMTP plugin. Compatible with best themes out there, is both a secure and responsive contact form p …
Document Feedback Developer Profile
213 plugins · 19.2M total installs
How We Detect Document Feedback
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/document-feedback/css/document-feedback-admin.css/wp-content/plugins/document-feedback/js/jquery.sparkline.min.js/wp-content/plugins/document-feedback/js/jquery.sparkline.min.jsdocument-feedback-admin.css?ver=jquery.sparkline.min.js?ver=HTML / DOM Fingerprints
document-feedback-metaboxdocument-feedback-chartdocument-feedback-legenddocument-feedback-legend-acceptdocument-feedback-legend-declinedocument-feedback-comment-wrapper<!--Do not delete these tags--><!--End Document Feedback-->data-document-feedback-formdata-document-feedback-form-messagedata-document-feedback-form-submitajaxurl<div id="document-feedback-form-container"><div id="document-feedback-form-prompt"><div id="document-feedback-form-response-message"><div id="document-feedback-form-submit-response">