
fVote Security & Risk Analysis
wordpress.org/plugins/fvoteA plugin for specific niche questions your vistors can vote for.
Is fVote Safe to Use in 2026?
Generally Safe
Score 85/100fVote has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "fvote" plugin v0.51 exhibits a mixed security posture. On the positive side, there are no known CVEs, no identified critical or high severity taint flows, and no dangerous functions detected in the static analysis. The attack surface is also relatively small, with only two shortcodes as entry points and no AJAX handlers or REST API routes that appear to be unprotected by default.
However, significant concerns arise from the lack of fundamental security practices in the codebase. All three detected SQL queries are executed without prepared statements, posing a substantial risk of SQL injection. Furthermore, none of the nine detected output operations are properly escaped, leaving the plugin vulnerable to cross-site scripting (XSS) attacks. The complete absence of nonce checks and capability checks, especially with shortcodes as entry points, further exacerbates these risks by allowing unauthenticated or unauthorized users to potentially trigger code execution or manipulate data.
The plugin's vulnerability history is clean, which is a positive sign, but it doesn't mitigate the immediate risks identified in the static analysis. The lack of past vulnerabilities could be due to the plugin's limited adoption or simply an oversight. In conclusion, while the plugin has a clean history, the current codebase contains critical vulnerabilities related to insecure SQL queries and unescaped output, compounded by a lack of essential authorization and nonce checks. These weaknesses create a high risk of exploitation.
Key Concerns
- SQL queries not using prepared statements
- Output not properly escaped
- Missing nonce checks
- Missing capability checks
fVote Security Vulnerabilities
fVote Release Timeline
fVote Code Analysis
SQL Query Safety
Output Escaping
fVote Attack Surface
Shortcodes 2
Maintenance & Trust
fVote Maintenance & Trust
Maintenance Signals
Community Trust
fVote Alternatives
Polls CP
cp-polls
Create classic polls and advanced polls with dependant questions. Voting / survey system.
WP Easy Poll
wp-easy-poll-afo
This is an easy to setup polling/ voting plugin for users. Create Polls from admin panel and display in widgets.
Votely by WPGens
votely-poll-vote-system-by-wpgens
Adds simple poll/vote/opinion system at the end of post that helps your content to engage with users. Check screenshots.
Kento Vote
kento-vote
Vote on Post and Display Who Voted via gravatar thumbnail.
WP Cool Poll
wp-cool-poll
This plugin makes it possible to create and manage a poll and display it in a widget.
fVote Developer Profile
12 plugins · 230 total installs
How We Detect fVote
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/fvote/fvote.js/wp-content/plugins/fvote/fvote.css/wp-content/plugins/fvote/fvote.jsfvote/fvote.js?ver=fvote/fvote.css?ver=HTML / DOM Fingerprints
fVote-formname="fVote"name="submit"<form name="fVote" action="<INPUT TYPE="submit" name="submit" value="