
Feature Request & Idea Collector Security & Risk Analysis
wordpress.org/plugins/feature-requestAdvanced Feature request and suggestion submitter with voting system for WordPress.
Is Feature Request & Idea Collector Safe to Use in 2026?
Generally Safe
Score 85/100Feature Request & Idea Collector has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "feature-request" plugin version 1.3.1 exhibits a mixed security posture. On the positive side, it has a clean vulnerability history with no known CVEs, and the taint analysis revealed no critical or high-severity issues. The majority of SQL queries utilize prepared statements, and there are a reasonable number of capability checks and nonce checks present.
However, the plugin does present several areas of concern. A significant portion of the attack surface, specifically 2 out of 14 entry points, are unprotected AJAX handlers. This is a notable risk as these handlers could be exploited by unauthenticated users. Furthermore, the presence of dangerous functions like `create_function` and `unserialize` raises red flags, as these can be vectors for code injection or deserialization vulnerabilities if not handled with extreme care and proper input validation. The relatively low percentage of properly escaped output (47%) also indicates a risk of Cross-Site Scripting (XSS) vulnerabilities.
In conclusion, while the plugin benefits from a lack of historical vulnerabilities, the static analysis reveals specific weaknesses that warrant attention. The unprotected AJAX endpoints and the use of dangerous functions are the most pressing issues. The low rate of proper output escaping also contributes to the overall risk profile. Addressing these points would significantly improve the plugin's security.
Key Concerns
- Unprotected AJAX handlers found
- Use of dangerous function: unserialize
- Use of dangerous function: create_function
- Low percentage of properly escaped output
- SQL queries with potential issues (25% not prepared)
Feature Request & Idea Collector Security Vulnerabilities
Feature Request & Idea Collector Release Timeline
Feature Request & Idea Collector Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Feature Request & Idea Collector Attack Surface
AJAX Handlers 12
Shortcodes 2
WordPress Hooks 27
Maintenance & Trust
Feature Request & Idea Collector Maintenance & Trust
Maintenance Signals
Community Trust
Feature Request & Idea Collector Alternatives
IdeaPush
ideapush
IdeaPush is a feature request management system for WordPress
Simple Feature Requests Free – User Feedback Board
simple-feature-requests
Collect and manage user feedback using your existing WordPress website. Prioritize the product features important to you and your customers.
Product Feature Request
product-feature-request
Product Feature Request plugin allows you to easily create and manage feature requests in your WordPress products.
Boomerang – Feature Request Platform
boomerang
A slick, modern feature request and feedback platform for WordPress. Visit us at boomerangwp.com.
FeedHub – Feedback Widget
feedhub-feedback-widget
Easily collect user feedback on your WordPress site with FeedHub's beautiful feedback widget.
Feature Request & Idea Collector Developer Profile
6 plugins · 310K total installs
How We Detect Feature Request & Idea Collector
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/feature-request/public/css/feature-request.css/wp-content/plugins/feature-request/public/js/feature-request.js/wp-content/plugins/feature-request/public/js/feature-request.jsfeature-request/public/css/feature-request.css?ver=feature-request/public/js/feature-request.js?ver=HTML / DOM Fingerprints
feature-request-wrapperfeature-request-formfeature-request-submit-button<!-- Feature Request Form --><!-- End Feature Request Form -->data-feature-request-iddata-feature-request-noncefeatureRequestAVFR_AJAX_URL/wp-json/feature-request/v1/submit/wp-json/feature-request/v1/vote[feature_request_form][feature_request_list]