
Marker.io – Visual Website Feedback Security & Risk Analysis
wordpress.org/plugins/marker-ioCollect visual website feedback from colleagues and clients on your WordPress site.
Is Marker.io – Visual Website Feedback Safe to Use in 2026?
Generally Safe
Score 99/100Marker.io – Visual Website Feedback has a strong security track record. Known vulnerabilities have been patched promptly.
The marker-io plugin version 1.2.2 presents a mixed security posture. On the positive side, the static analysis reveals a clean attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are directly exposed. The code also demonstrates good practices by utilizing prepared statements for all SQL queries and implementing nonce and capability checks. However, the presence of two known medium severity CVEs, both related to Cross-Site Request Forgery (CSRF), is a significant concern. While these vulnerabilities are currently unpatched, their historical nature suggests potential for remediation in later versions, but the fact they existed at all warrants caution. The high percentage of properly escaped output (85%) is a strength, but the remaining 15% could still be a vector for certain types of cross-site scripting (XSS) attacks, though no specific taint flows were identified in this analysis. The lack of identified taint flows or dangerous functions is positive, but it does not negate the historical vulnerability data. Overall, while the current code seems to have a good foundation for security, the past vulnerabilities cannot be ignored and suggest that thorough review and patching are crucial for this plugin.
Key Concerns
- Two medium severity CVEs
- 15% of output unescaped
Marker.io – Visual Website Feedback Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Marker.io <= 1.1.8 - Cross-Site Request Forgery
Marker.io <= 1.1.6 - Cross-Site Request Forgery
Marker.io – Visual Website Feedback Code Analysis
Output Escaping
Marker.io – Visual Website Feedback Attack Surface
WordPress Hooks 7
Maintenance & Trust
Marker.io – Visual Website Feedback Maintenance & Trust
Maintenance Signals
Community Trust
Marker.io – Visual Website Feedback Alternatives
Feedbucket – Website Feedback Tool
feedbucket
Enable your clients and team members to submit feedback using screenshot and recordings on your WordPress site.
PageProofer
pageproofer
Allow developers, designers, clients and site visitors to easily leave feedback directly on your website.
Superflow: Markup live websites
superflow
Comment and collaborate directly on your live Wordpress website.
Ybug Feedback Widget
ybug-feedback-widget
Collect visual feedback and bug reports with screenshots from your users. This plugin allows you to easily add Ybug Feedback Widget on your website.
Webvizio
webvizio
The Ultimate Visual Feedback, Collaboration & Productivity Tool for Web Professionals.
Marker.io – Visual Website Feedback Developer Profile
1 plugin · 4K total installs
How We Detect Marker.io – Visual Website Feedback
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/marker-io/markerio-icons.css/wp-content/plugins/marker-io/dist/styles.css/wp-content/plugins/marker-io/dist/scripts.js/wp-content/plugins/marker-io/dist/scripts.jsmarkerio_style?ver=markerio_script?ver=HTML / DOM Fingerprints
id="app"__MarkermarkerConfigmarkerioPluginOptionsmarkerioAvailableUserRolesmarkerioAvailablePostTypesmarkerioCanMa