
FeedHub – Feedback Widget Security & Risk Analysis
wordpress.org/plugins/feedhub-feedback-widgetEasily collect user feedback on your WordPress site with FeedHub's beautiful feedback widget.
Is FeedHub – Feedback Widget Safe to Use in 2026?
Generally Safe
Score 100/100FeedHub – Feedback Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The feedhub-feedback-widget plugin, version 1.0.2, demonstrates a generally strong security posture based on the provided static analysis. The code shows excellent adherence to security best practices, with 100% of SQL queries utilizing prepared statements and all output properly escaped. The absence of dangerous functions, file operations, and external HTTP requests further contributes to a reduced attack surface. The limited entry points, consisting solely of one shortcode, are also a positive indicator. Furthermore, the plugin has no recorded vulnerabilities, including CVEs, suggesting a history of stable and secure development.
However, a notable concern arises from the lack of nonce checks across all entry points, including the single shortcode. While the code has capability checks, the absence of nonces leaves it potentially susceptible to Cross-Site Request Forgery (CSRF) attacks, where an attacker could trick a logged-in user into executing unintended actions. The taint analysis reporting zero flows is positive, but this is based on zero analyzed flows, making it difficult to definitively rule out potential taint issues. Despite the clean vulnerability history, the absence of nonce checks represents a tangible, albeit addressable, risk that should be prioritized.
In conclusion, feedhub-feedback-widget v1.0.2 is well-coded with robust practices regarding SQL and output escaping. Its lack of known vulnerabilities is commendable. The primary weakness lies in the missing nonce checks, which introduces a CSRF risk. Addressing this would significantly strengthen the plugin's overall security.
Key Concerns
- Missing nonce checks on entry points
FeedHub – Feedback Widget Security Vulnerabilities
FeedHub – Feedback Widget Code Analysis
Output Escaping
FeedHub – Feedback Widget Attack Surface
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
FeedHub – Feedback Widget Maintenance & Trust
Maintenance Signals
Community Trust
FeedHub – Feedback Widget Alternatives
Hark — Customer Suggestions
hark-customer-suggestions
Let your customers tell you what they want. Hark adds a suggestion widget to your site so visitors can request products.
Marker.io – Visual Website Feedback
marker-io
Collect visual website feedback from colleagues and clients on your WordPress site.
BNE Testimonials
bne-testimonials
Display testimonials and reviews on any page or widget area as list or slider. Upgrade to PRO for additional layouts, themes, submission form, API, ra …
Feedbucket – Website Feedback Tool
feedbucket
Enable your clients and team members to submit feedback using screenshot and recordings on your WordPress site.
Survicate
survicate
With Survicate, you can collect feedback using contextual surveys that feel like a part of your website.
FeedHub – Feedback Widget Developer Profile
1 plugin · 0 total installs
How We Detect FeedHub – Feedback Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/feedhub-feedback-widget/assets/admin.css/wp-content/plugins/feedhub-feedback-widget/assets/admin.js/wp-content/plugins/feedhub-feedback-widget/feedhub.phpfeedhub-feedback-widget/assets/admin.css?ver=feedhub-feedback-widget/assets/admin.js?ver=HTML / DOM Fingerprints
feedhub-widgetfeedhub-buttondata-feedhub-widget-keydata-feedhub-app-slugFeedHubWidget[feedhub]