
FourEyes Security & Risk Analysis
wordpress.org/plugins/foureyesThe FourEyes Plugin makes it quick and easy to embed surveys onto your Wordpress posts or pages.
Is FourEyes Safe to Use in 2026?
Generally Safe
Score 85/100FourEyes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The foureyes v1.0.1 plugin exhibits a strong security posture based on the provided static analysis. There are no identified dangerous functions, SQL injection vulnerabilities, or output escaping issues, indicating good development practices in these areas. The absence of external HTTP requests and file operations further reduces the potential attack surface. The plugin also has no recorded vulnerability history, suggesting a consistent focus on security by its developers.
However, a significant concern arises from the complete lack of nonces and capability checks. While the attack surface is currently zero, this omission represents a critical weakness. If any entry points (AJAX, REST API, shortcodes) were to be introduced in future versions without proper authorization checks, the plugin would be highly susceptible to various attacks. The absence of taint analysis findings is positive, but the lack of any identified entry points makes it impossible to definitively conclude on its robustness against complex, chained exploits.
In conclusion, foureyes v1.0.1 is currently a very low-risk plugin due to its limited functionality and absence of known vulnerabilities. The development team has clearly followed best practices regarding SQL queries and output escaping. The primary weakness is the lack of authorization checks, which, while not a current exploit, leaves the plugin vulnerable should its attack surface expand. A strong recommendation would be to implement nonces and capability checks on any future functionality.
Key Concerns
- Missing nonce checks
- Missing capability checks
FourEyes Security Vulnerabilities
FourEyes Code Analysis
Output Escaping
FourEyes Attack Surface
WordPress Hooks 3
Maintenance & Trust
FourEyes Maintenance & Trust
Maintenance Signals
Community Trust
FourEyes Alternatives
Qualtrics Survey Embeds
qualtrics-survey-embeds
Adds a Qualtrics Embed Handler to WordPress allowing for quick survey embeds.
UserFeedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds
userfeedback-lite
Ultimate user feedback plugin to ask questions, surveys, polls, from your website in seconds
Crowdsignal Forms
crowdsignal-forms
The Crowdsignal Forms plugin allows you to create and manage polls right from within the block editor.
Crowdsignal Dashboard – Polls, Surveys & more
polldaddy
Manage your Crowdsignal polls, surveys, quizzes, and ratings directly from the WordPress dashboard.
TrustMate.io – WooCommerce integration
trustmate-io-integration-for-woocommerce
TrustMate - Reviews for your shop and products at you WooCommerce site. Generate valuable traffic and profit more than others!
FourEyes Developer Profile
2 plugins · 310 total installs
How We Detect FourEyes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/foureyes/js/embed.jsHTML / DOM Fingerprints
foureyes-embeddata-survey<script src="https://getfoureyes.com/js/embed.js">{"url":"https://getfoureyes.com/s/"}</script><div class="foureyes-embed"