
Event Voting & Live Leaderboard by Clicksmith Security & Risk Analysis
wordpress.org/plugins/event-voting-live-leaderboard-by-clicksmithLive event voting with category limits, quick ballots, spam protection, and a real-time leaderboard for big screens.
Is Event Voting & Live Leaderboard by Clicksmith Safe to Use in 2026?
Generally Safe
Score 100/100Event Voting & Live Leaderboard by Clicksmith has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "event-voting-live-leaderboard-by-clicksmith" v1.0.4 exhibits a mixed security posture. On the positive side, it has no known CVEs, no critical or high severity taint flows, and a relatively low number of file operations and external HTTP requests. The majority of SQL queries are properly prepared, and there's a decent number of nonce and capability checks. However, there are clear areas of concern that warrant attention.
The main risk stems from the attack surface. The plugin exposes 7 total entry points, and significantly, 2 of these are AJAX handlers that lack authentication checks. This presents a direct avenue for unauthenticated users to potentially interact with sensitive backend functions. Furthermore, while most SQL queries are prepared, the presence of 13 total queries means there's still a possibility for issues if the remaining ones are vulnerable. The output escaping is also a concern, with only 60% properly escaped, increasing the risk of cross-site scripting (XSS) vulnerabilities.
The lack of any recorded vulnerability history is generally a good sign, suggesting a history of security consciousness or simply good fortune. However, it doesn't negate the immediate risks identified in the static analysis. The plugin has strengths in its lack of dangerous functions and external requests, but the unprotected AJAX endpoints and the moderate percentage of unescaped output are notable weaknesses that could be exploited.
Key Concerns
- Unprotected AJAX handlers
- Moderate percentage of unescaped output
Event Voting & Live Leaderboard by Clicksmith Security Vulnerabilities
Event Voting & Live Leaderboard by Clicksmith Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Event Voting & Live Leaderboard by Clicksmith Attack Surface
AJAX Handlers 4
Shortcodes 3
WordPress Hooks 15
Maintenance & Trust
Event Voting & Live Leaderboard by Clicksmith Maintenance & Trust
Maintenance Signals
Community Trust
Event Voting & Live Leaderboard by Clicksmith Alternatives
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe
contest-gallery
JPG, PNG, MP4, MP3, PDF, ZIP & more. Create voting & uploading galleries for photos & media. Social Share, User Registration & Sell via PayPal/Stripe.
Photo Competition Manager
photo-competition-manager
Complete photography club competition platform. Handle submissions, member voting, public voting, email notifications, and beautiful results displays.
The Events Calendar
the-events-calendar
The Events Calendar: #1 calendar plugin for WordPress. Create/manage events (virtual too!) on your site with the free plugin.
LatePoint – Calendar Booking Plugin for Appointments and Events
latepoint
Optimize your appointment scheduling with our plugin. Sync calendars, automate reminders, and keep your bookings organized.
kk Star Ratings – Rate Post & Collect User Feedbacks
kk-star-ratings
kk Star Ratings allows blog visitors to involve and interact more effectively with your website by rating posts.
Event Voting & Live Leaderboard by Clicksmith Developer Profile
2 plugins · 0 total installs
How We Detect Event Voting & Live Leaderboard by Clicksmith
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/event-voting-live-leaderboard-by-clicksmith/assets/css/csvote.css/wp-content/plugins/event-voting-live-leaderboard-by-clicksmith/assets/js/csvote.js/wp-content/plugins/event-voting-live-leaderboard-by-clicksmith/assets/js/jquery-countdown.min.js/wp-content/plugins/event-voting-live-leaderboard-by-clicksmith/assets/js/sortable.min.js/wp-content/plugins/event-voting-live-leaderboard-by-clicksmith/assets/js/jquery-countdown.min.js/wp-content/plugins/event-voting-live-leaderboard-by-clicksmith/assets/js/sortable.min.js/wp-content/plugins/event-voting-live-leaderboard-by-clicksmith/assets/js/csvote.jsevent-voting-live-leaderboard-by-clicksmith/assets/css/csvote.css?ver=event-voting-live-leaderboard-by-clicksmith/assets/js/csvote.js?ver=event-voting-live-leaderboard-by-clicksmith/assets/js/jquery-countdown.min.js?ver=event-voting-live-leaderboard-by-clicksmith/assets/js/sortable.min.js?ver=HTML / DOM Fingerprints
csvote-brandcsvote-brand__rowcsvote-brand__logocsvote-brand__mutedcsvote-notice-- BEGIN Clicksmith Event Voting Branding ---- END Clicksmith Event Voting Branding --<!-- Clicksmith Event Voting: Shortcode Wrapper --><!-- End Clicksmith Event Voting: Shortcode Wrapper -->+4 moredata-csvote-event-iddata-csvote-vote-iddata-csvote-post-iddata-csvote-noncedata-csvote-actiondata-csvote-limit+25 moreCSVOTE_AJAX_URLCSVOTE_NONCECSVOTE_SETTINGSCSVOTE_VOTING_ENABLEDCSVOTE_LEADERBOARD_ENABLEDCSVOTE_WINNERS_ENABLED+39 more/wp-json/csvote/v1/vote/wp-json/csvote/v1/leaderboard/wp-json/csvote/v1/winners<div class='csvote-notice'>Event Voting: shortcode could not be rendered. Check that the core class and methods exist.</div>