
FeedHub – Feedback Widget Security & Risk Analysis
wordpress.org/plugins/feedhub-feedback-widgetEasily collect user feedback on your WordPress site with FeedHub's beautiful feedback widget.
Is FeedHub – Feedback Widget Safe to Use in 2026?
Generally Safe
Score 100/100FeedHub – Feedback Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The feedhub-feedback-widget plugin, version 1.0.2, demonstrates a generally strong security posture based on the provided static analysis. The code shows excellent adherence to security best practices, with 100% of SQL queries utilizing prepared statements and all output properly escaped. The absence of dangerous functions, file operations, and external HTTP requests further contributes to a reduced attack surface. The limited entry points, consisting solely of one shortcode, are also a positive indicator. Furthermore, the plugin has no recorded vulnerabilities, including CVEs, suggesting a history of stable and secure development.
However, a notable concern arises from the lack of nonce checks across all entry points, including the single shortcode. While the code has capability checks, the absence of nonces leaves it potentially susceptible to Cross-Site Request Forgery (CSRF) attacks, where an attacker could trick a logged-in user into executing unintended actions. The taint analysis reporting zero flows is positive, but this is based on zero analyzed flows, making it difficult to definitively rule out potential taint issues. Despite the clean vulnerability history, the absence of nonce checks represents a tangible, albeit addressable, risk that should be prioritized.
In conclusion, feedhub-feedback-widget v1.0.2 is well-coded with robust practices regarding SQL and output escaping. Its lack of known vulnerabilities is commendable. The primary weakness lies in the missing nonce checks, which introduces a CSRF risk. Addressing this would significantly strengthen the plugin's overall security.
Key Concerns
- Missing nonce checks on entry points
FeedHub – Feedback Widget Security Vulnerabilities
FeedHub – Feedback Widget Release Timeline
FeedHub – Feedback Widget Code Analysis
Output Escaping
FeedHub – Feedback Widget Attack Surface
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
FeedHub – Feedback Widget Maintenance & Trust
Maintenance Signals
Community Trust
FeedHub – Feedback Widget Alternatives
Boomerang – Feature Request Platform
boomerang
A slick, modern feature request and feedback platform for WordPress. Visit us at boomerangwp.com.
Hark — Customer Suggestions
hark-customer-suggestions
Let your customers tell you what they want. Hark adds a suggestion widget to your site so visitors can request products.
Inline Feedback Widget
inline-feedback-widget
Collect user feedback with a lightweight widget. Connect your workspace, configure visibility, and start gathering insights in seconds.
UseResponse Feedback Widget
useresponse-feedback-widget
Collect feedback within your WordPress website with an easy-to-use and customizable widget from UseResponse.
Marker.io – Visual Website Feedback
marker-io
Collect visual website feedback from colleagues and clients on your WordPress site.
FeedHub – Feedback Widget Developer Profile
1 plugin · 0 total installs
How We Detect FeedHub – Feedback Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/feedhub-feedback-widget/assets/admin.css/wp-content/plugins/feedhub-feedback-widget/assets/admin.js/wp-content/plugins/feedhub-feedback-widget/feedhub.phpfeedhub-feedback-widget/assets/admin.css?ver=feedhub-feedback-widget/assets/admin.js?ver=HTML / DOM Fingerprints
feedhub-widgetfeedhub-buttondata-feedhub-widget-keydata-feedhub-app-slugFeedHubWidget[feedhub]