
Free Feedback Form Plugin Security & Risk Analysis
wordpress.org/plugins/kampyle-integrator-for-wordpressAdd the Kampyle code required to integrate it to your WordPress site
Is Free Feedback Form Plugin Safe to Use in 2026?
Generally Safe
Score 85/100Free Feedback Form Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The kampyle-integrator-for-wordpress plugin, version 1.0, exhibits a mixed security posture. On the positive side, it demonstrates an absence of known vulnerabilities and CVEs, suggesting a generally stable history. The code analysis indicates a lack of dangerous functions, file operations, and external HTTP requests, which are common vectors for exploitation. Furthermore, all SQL queries utilize prepared statements, a crucial security practice. However, there are significant concerns regarding output escaping. With 100% of its outputs not properly escaped, the plugin presents a high risk of cross-site scripting (XSS) vulnerabilities. This means that any data displayed to users, if it originates from an untrusted source, could be manipulated to inject malicious scripts, potentially leading to session hijacking, data theft, or defacement.
While the plugin has a clean vulnerability history and appears to have a limited attack surface from the static analysis (0 AJAX handlers, REST API routes, shortcodes, and cron events without protection), the critical flaw in output escaping overshadows these strengths. The presence of a nonce check is a positive sign, but its effectiveness is limited without corresponding authorization checks on critical functionalities, though none were explicitly found in the static analysis that are exposed. The lack of any recorded vulnerabilities historically could indicate either a very mature and secure development process or simply a lack of widespread usage and targeted attacks. Regardless, the unescaped output is a glaring security weakness that must be addressed.
Key Concerns
- All outputs are unescaped
- No capability checks on entry points
Free Feedback Form Plugin Security Vulnerabilities
Free Feedback Form Plugin Code Analysis
Output Escaping
Free Feedback Form Plugin Attack Surface
WordPress Hooks 2
Maintenance & Trust
Free Feedback Form Plugin Maintenance & Trust
Maintenance Signals
Community Trust
Free Feedback Form Plugin Alternatives
UserFeedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds
userfeedback-lite
Ultimate user feedback plugin to ask questions, surveys, polls, from your website in seconds
WP ULike – Like & Dislike Buttons for Engagement and Feedback
wp-ulike
Voting buttons that let your visitors give instant feedback. See what your audience loves with no registration, no friction, just one click.
Contact Form & SMTP Plugin for WordPress by PirateForms
pirate-forms
A simple and effective WordPress contact form & SMTP plugin. Compatible with best themes out there, is both a secure and responsive contact form p …
Contact Form Clean and Simple
clean-and-simple-contact-form-by-meg-nicholas
A clean and simple contact form with flexible CSS framework support.
Feedback Button – Jotform
jotform-feedback-button
Display a beautiful feedback button on the side of your blog. When a reader clicks on it a feedback form pops up. Completely customizable.
Free Feedback Form Plugin Developer Profile
3 plugins · 60 total installs
How We Detect Free Feedback Form Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
crazyegg