
Feedbucket – Website Feedback Tool Security & Risk Analysis
wordpress.org/plugins/feedbucketEnable your clients and team members to submit feedback using screenshot and recordings on your WordPress site.
Is Feedbucket – Website Feedback Tool Safe to Use in 2026?
Generally Safe
Score 99/100Feedbucket – Website Feedback Tool has a strong security track record. Known vulnerabilities have been patched promptly.
The feedbucket plugin, version 1.0.10, exhibits a generally good security posture based on the static analysis. A significant strength is the complete absence of raw SQL queries; all queries are prepared, mitigating SQL injection risks. Furthermore, the plugin demonstrates an awareness of security best practices by including nonce and capability checks on its entry points. The attack surface is minimal, with only one AJAX handler, and notably, it does not appear to have any unprotected entry points. Taint analysis also shows no unsanitized paths, which is a positive indicator for preventing more complex injection vulnerabilities.
However, there are areas for improvement. While most outputs are escaped, a notable percentage (33%) are not properly escaped. This could lead to Cross-Site Scripting (XSS) vulnerabilities if the unescaped data is user-controlled or originates from an untrusted source. The plugin's vulnerability history, while showing no currently unpatched CVEs, does indicate a past medium-severity vulnerability, and a pattern of Cross-Site Request Forgery (CSRF) issues were previously identified. This suggests that while recent versions might be more secure, historical issues should still be monitored, and the codebase might require ongoing vigilance for such vulnerabilities.
In conclusion, feedbucket 1.0.10 is reasonably secure due to its robust handling of SQL and its limited, protected attack surface. The presence of proper checks on entry points is commendable. The primary concern lies with the unescaped output, which presents a potential XSS risk. The historical vulnerability data, though not indicating current critical threats, suggests a need for continued security reviews to ensure past vulnerability types do not resurface.
Key Concerns
- Unescaped output present
- Past medium vulnerability history
- Past CSRF vulnerability history
Feedbucket – Website Feedback Tool Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Feedbucket – Website Feedback Tool <= 1.0.6 - Cross-Site Request Forgery
Feedbucket – Website Feedback Tool Code Analysis
Output Escaping
Data Flow Analysis
Feedbucket – Website Feedback Tool Attack Surface
AJAX Handlers 1
WordPress Hooks 5
Maintenance & Trust
Feedbucket – Website Feedback Tool Maintenance & Trust
Maintenance Signals
Community Trust
Feedbucket – Website Feedback Tool Alternatives
Marker.io – Visual Website Feedback
marker-io
Collect visual website feedback from colleagues and clients on your WordPress site.
PageProofer
pageproofer
Allow developers, designers, clients and site visitors to easily leave feedback directly on your website.
Superflow: Markup live websites
superflow
Comment and collaborate directly on your live Wordpress website.
Ybug Feedback Widget
ybug-feedback-widget
Collect visual feedback and bug reports with screenshots from your users. This plugin allows you to easily add Ybug Feedback Widget on your website.
Webvizio
webvizio
The Ultimate Visual Feedback, Collaboration & Productivity Tool for Web Professionals.
Feedbucket – Website Feedback Tool Developer Profile
1 plugin · 1K total installs
How We Detect Feedbucket – Website Feedback Tool
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/feedbucket/dist/styles.css/wp-content/plugins/feedbucket/dist/vue.jsfeedbucket/dist/styles.css?ver=HTML / DOM Fingerprints
data-feedbucketwindow.feedbucketConfig