
IaVote Security & Risk Analysis
wordpress.org/plugins/iavoteIaVote enables bloggers to add voting functionality to their posts. Include 2 widgets: resume votes and most voted.
Is IaVote Safe to Use in 2026?
Generally Safe
Score 85/100IaVote has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The iavote v1.0 plugin exhibits a concerning security posture despite a seemingly small attack surface and no recorded vulnerability history. While the static analysis indicates zero entry points, this is misleading as the taint analysis reveals a single flow with an unsanitized path, which is categorized as high severity. This indicates a potential for injecting malicious data that is not properly validated or neutralized before being used in a sensitive operation. Furthermore, the complete absence of output escaping across all analyzed outputs is a critical weakness. This means that any data rendered to the user could potentially contain cross-site scripting (XSS) payloads, allowing attackers to execute arbitrary JavaScript in the user's browser. The lack of capability checks and nonce checks also raises concerns about potential unauthorized actions or privilege escalation if an attacker can find a way to trigger certain code paths, even if they are not explicitly exposed as entry points. The absence of known CVEs is a positive sign but does not negate the presence of critical flaws identified in the code analysis. Overall, while the plugin has strengths in avoiding known dangerous functions and primarily using prepared statements for SQL, the unaddressed high-severity taint flow and the complete lack of output escaping present significant risks that require immediate attention.
Key Concerns
- High severity unsanitized path in taint flow
- 0% output escaping
- 0 nonce checks
- 0 capability checks
IaVote Security Vulnerabilities
IaVote Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
IaVote Attack Surface
WordPress Hooks 1
Maintenance & Trust
IaVote Maintenance & Trust
Maintenance Signals
Community Trust
IaVote Alternatives
Crowdsignal Dashboard – Polls, Surveys & more
polldaddy
Manage your Crowdsignal polls, surveys, quizzes, and ratings directly from the WordPress dashboard.
WP-Polls
wp-polls
Adds an AJAX poll system to your WordPress blog. You can also easily add a poll into your WordPress's blog post/page.
WP-PostRatings
wp-postratings
Adds an AJAX rating system for your WordPress site's content.
Democracy Poll
democracy-poll
WordPress polls plugin with multiple-choice, custom answers, cache compatibility, widgets, and shortcodes.
Poll Maker – Versus Polls, Anonymous Polls, Image Polls
poll-maker
Poll Maker is a FREE WordPress poll plugin that will let you create customizable and professional online polls and voting for your WordPress website.
IaVote Developer Profile
1 plugin · 10 total installs
How We Detect IaVote
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/iavote/iavote.css/wp-content/plugins/iavote/iavote.jsHTML / DOM Fingerprints
vote-okvote-kolinkvote-oklinkvote-koiavoteupiavotedownnovote-oknovote-ko+7 moreCopyright Felipe Gonzalez Lopez (email : reg@informaticaautonomos.com)This program is free software; you can redistribute it and/or modifyit under the terms of the GNU General Public License as published bythe Free Software Foundation; either version 2 of the License, or+11 moreid="linkiavoteupid="iavoteupid="linkiavotedownid="iavotedownid="novote-okid="novote-ko+1 moreiavotegetUserId<div class="tabbertab"><h2><div class="right-list"><h3><a href