
FeedFocal Security & Risk Analysis
wordpress.org/plugins/feedfocalCollect user feedback with our easy to use survey tools! Create surveys in seconds.
Is FeedFocal Safe to Use in 2026?
Generally Safe
Score 100/100FeedFocal has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin "feedfocal" v1.3.2 demonstrates several good security practices, including the absence of dangerous functions, all SQL queries using prepared statements, and no file operations or external HTTP requests. The attack surface is also relatively small and appears to be protected, with no unprotected entry points identified in the static analysis. However, there are notable concerns regarding output escaping, with only one-third of identified outputs being properly escaped, which could lead to cross-site scripting vulnerabilities. Furthermore, the complete absence of nonce checks, while not directly linked to an unprotected entry point in this static scan, represents a potential weakness in preventing CSRF attacks, especially if new AJAX handlers or other functionalities were to be added without proper checks.
The vulnerability history reveals a past medium-severity CVE related to missing authorization. While this vulnerability is currently unpatched, it is no longer present in this specific version, suggesting it was addressed in a prior release. However, the pattern of a past authorization issue, coupled with the presence of only one capability check in the current static analysis, warrants attention. This could indicate a broader trend of insufficient authorization checks or a reliance on only a single point of defense, which is a risk if that single check is bypassed or insufficient for all potential attack vectors. Overall, the plugin has a decent security posture with some important areas for improvement, particularly in output sanitization and potentially a more comprehensive approach to authorization checks.
Key Concerns
- Unescaped output found
- Vulnerability history: 1 medium CVE (Missing Authorization)
- No nonce checks found
FeedFocal Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
FeedFocal <= 1.2.2 - Missing Authorization via feedfocal_api_setup REST function
FeedFocal Code Analysis
Output Escaping
FeedFocal Attack Surface
REST API Routes 1
WordPress Hooks 9
Maintenance & Trust
FeedFocal Maintenance & Trust
Maintenance Signals
Community Trust
FeedFocal Alternatives
UserFeedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds
userfeedback-lite
Ultimate user feedback plugin to ask questions, surveys, polls, from your website in seconds
Mopinion Feedback Form
mopinion-feedback-form
Easy add feedback buttons and feedback forms to your website with the Mopinion.com Wordpress Plugin. Easy install, fast user insights.
Exit Intent Visitors Feedback – Trigger Feedback Popup on Exit Intent
visitors-feedback
Capture valuable feedback from your website visitors before they leave from your website.
zenloop for WooCommerce – Net Promoter Score (NPS) platform
zenloop-woocommerce-nps-platform
zenloop for WooCommerce is the official zenloop.com plugin. It connects zenloop’s Net Promoter Score (NPS) platform with your WooCommerce shop.
Katorymnd Reaction Process Plugin
katorymnd-reaction-process
Elevate your WordPress site with dynamic feedback, ratings, and surveys for insightful user interaction.
FeedFocal Developer Profile
1 plugin · 2K total installs
How We Detect FeedFocal
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/feedfocal/css/uikit.css/wp-content/plugins/feedfocal/css/feedfocal-admin.css/wp-content/plugins/feedfocal/js/uikit.js/wp-content/plugins/feedfocal/js/feedfocal-admin.js/wp-content/plugins/feedfocal/js/feedfocal-admin.js/wp-content/plugins/feedfocal/js/uikit.jsfeedfocal-admin.css?ver=uikit.css?ver=feedfocal-admin.js?ver=uikit.js?ver=HTML / DOM Fingerprints
page-feedfocaldata-uk-nav=""WPURLS/wp-json/feedfocal/v1/setup