
FeedbackVault Security & Risk Analysis
wordpress.org/plugins/feedbackvaultProfessional WordPress plugin for displaying authentic reviews from Google My Business and Trustpilot with exact design matching.
Is FeedbackVault Safe to Use in 2026?
Generally Safe
Score 100/100FeedbackVault has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "feedbackvault" v1.0.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for all SQL queries and maintaining a high percentage of properly escaped output. Furthermore, the absence of any recorded vulnerabilities or CVEs suggests a history of responsible development and patching. The code analysis also shows no dangerous functions, file operations, or critical taint flows.
However, significant concerns arise from the attack surface. A substantial portion of the plugin's AJAX handlers (8 out of 9) lack proper authentication checks. This is a critical weakness that could allow unauthenticated users to trigger potentially harmful actions or expose sensitive information through these endpoints. The presence of only 3 nonce checks across 9 AJAX handlers further exacerbates this risk. While the overall vulnerability history is clean, the unprotected AJAX endpoints represent a clear and present danger that needs immediate attention. The plugin's strengths in SQL and output handling are overshadowed by the critical exposure of its AJAX functionality.
Key Concerns
- 8/9 AJAX handlers unprotected
- Low number of nonce checks on AJAX
FeedbackVault Security Vulnerabilities
FeedbackVault Release Timeline
FeedbackVault Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
FeedbackVault Attack Surface
AJAX Handlers 9
Shortcodes 19
WordPress Hooks 28
Maintenance & Trust
FeedbackVault Maintenance & Trust
Maintenance Signals
Community Trust
FeedbackVault Alternatives
Better Business Reviews – Trustpilot WordPress Plugin
better-business-reviews
Better Business Reviews allows you to display your business reviews from a Trustpilot profile.
Revix Reviews – All-in-One Business Review Manager
revix-reviews
Revix Reviews helps you collect, import, and display reviews—including Trustpilot and Google—with more platforms coming soon.
Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More
reviews-feed
No API key required. Display Yelp and Google reviews for any business in a clean, customizable feed on your site.
Rich Showcase for Google Reviews
widget-google-reviews
Display up to 10 Google reviews in less than a minute. Continue collecting new reviews. No limits on connected places, widgets, shortcodes and blocks.
Site Reviews
site-reviews
Site Reviews is a complete review management solution that integrates with WooCommerce and SureCart and works similarly to reviews on Amazon, Tripadvi …
FeedbackVault Developer Profile
1 plugin · 0 total installs
How We Detect FeedbackVault
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/feedbackvault/Public/Assets/css/style.css/wp-content/plugins/feedbackvault/Public/Assets/js/script.js/wp-content/plugins/feedbackvault/Public/Assets/js/script.jsfeedbackvault/style.css?ver=feedbackvault/script.js?ver=HTML / DOM Fingerprints
feedbackvault-admin-stylesfeedbackvault-admin-scriptsdata-feedbackvault-settingsfeedbackvault_admin