
Gleap Security & Risk Analysis
wordpress.org/plugins/gleapAll-in-one customer feedback tool for websites. Learn more at https://www.gleap.io
Is Gleap Safe to Use in 2026?
Generally Safe
Score 100/100Gleap has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of Gleap v13.0.10 reveals a generally strong security posture. The absence of dangerous functions, reliance on prepared statements for all SQL queries, and proper output escaping are significant strengths. Furthermore, the plugin has no recorded vulnerabilities, which is a positive indicator. However, there are a few areas that warrant attention. The plugin makes one external HTTP request, which could be a vector for issues if not handled securely (though no specific issues are flagged in the provided data). Crucially, the complete lack of nonce checks and capability checks across all entry points is a significant concern. While the attack surface appears to be zero, this absence of authorization and integrity checks means that if any entry points were to be discovered or introduced in the future, they would be inherently unprotected.
Key Concerns
- No nonce checks on entry points
- No capability checks on entry points
- Single external HTTP request (potential risk)
Gleap Security Vulnerabilities
Gleap Code Analysis
Gleap Attack Surface
WordPress Hooks 10
Maintenance & Trust
Gleap Maintenance & Trust
Maintenance Signals
Community Trust
Gleap Alternatives
Ybug Feedback Widget
ybug-feedback-widget
Collect visual feedback and bug reports with screenshots from your users. This plugin allows you to easily add Ybug Feedback Widget on your website.
Buglog
buglog
Bug Reporting Tool for Websites.
UserFeedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds
userfeedback-lite
Ultimate user feedback plugin to ask questions, surveys, polls, from your website in seconds
Marker.io – Visual Website Feedback
marker-io
Collect visual website feedback from colleagues and clients on your WordPress site.
FeedFocal
feedfocal
Collect user feedback with our easy to use survey tools! Create surveys in seconds.
Gleap Developer Profile
1 plugin · 300 total installs
How We Detect Gleap
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gleap/assets/css/gleap.css/wp-content/plugins/gleap/assets/js/gleap.js/wp-content/plugins/gleap/assets/js/gleap-init.jsgleap/assets/css/gleap.css?ver=gleap/assets/js/gleap.js?ver=gleap/assets/js/gleap-init.js?ver=HTML / DOM Fingerprints
gleap-widgetgleap-feedback-buttongleap-chat-wrapper<!-- Gleap widget -->data-gleap-tokendata-gleap-app-idwindow.Gleapvar GleapInit