Marker.io – Visual Website Feedback Security & Risk Analysis

wordpress.org/plugins/marker-io

Collect visual website feedback from colleagues and clients on your WordPress site.

4K active installs v1.2.2 PHP 5.6+ WP 4.7+ Updated Dec 18, 2025
bug-trackingfeedbackfeedback-widgetvisual-feedbackwebsite-feedback
99
A · Safe
CVEs total2
Unpatched0
Last CVEApr 10, 2024
Safety Verdict

Is Marker.io – Visual Website Feedback Safe to Use in 2026?

Generally Safe

Score 99/100

Marker.io – Visual Website Feedback has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Apr 10, 2024Updated 3mo ago
Risk Assessment

The marker-io plugin version 1.2.2 presents a mixed security posture. On the positive side, the static analysis reveals a clean attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are directly exposed. The code also demonstrates good practices by utilizing prepared statements for all SQL queries and implementing nonce and capability checks. However, the presence of two known medium severity CVEs, both related to Cross-Site Request Forgery (CSRF), is a significant concern. While these vulnerabilities are currently unpatched, their historical nature suggests potential for remediation in later versions, but the fact they existed at all warrants caution. The high percentage of properly escaped output (85%) is a strength, but the remaining 15% could still be a vector for certain types of cross-site scripting (XSS) attacks, though no specific taint flows were identified in this analysis. The lack of identified taint flows or dangerous functions is positive, but it does not negate the historical vulnerability data. Overall, while the current code seems to have a good foundation for security, the past vulnerabilities cannot be ignored and suggest that thorough review and patching are crucial for this plugin.

Key Concerns

  • Two medium severity CVEs
  • 15% of output unescaped
Vulnerabilities
2

Marker.io – Visual Website Feedback Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2024-31427medium · 4.3Cross-Site Request Forgery (CSRF)

Marker.io <= 1.1.8 - Cross-Site Request Forgery

Apr 10, 2024 Patched in 1.1.9 (7d)
WF-c49b3841-370b-42ed-9545-e69c2544642d-marker-iomedium · 4.3Cross-Site Request Forgery (CSRF)

Marker.io <= 1.1.6 - Cross-Site Request Forgery

Oct 3, 2023 Patched in 1.1.7 (112d)
Code Analysis
Analyzed Mar 16, 2026

Marker.io – Visual Website Feedback Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
17 escaped
Nonce Checks
2
Capability Checks
4
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

85% escaped20 total outputs
Attack Surface

Marker.io – Visual Website Feedback Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_enqueue_scriptsmarker-io.php:36
actionwp_headmarker-io.php:179
actionadmin_headmarker-io.php:180
actionadmin_menumarker-io.php:193
actionmarkerio_default_optionsmarker-io.php:222
actionadmin_initmarker-io.php:279
filterplugin_action_links_marker-io/marker-io.phpmarker-io.php:295
Maintenance & Trust

Marker.io – Visual Website Feedback Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 18, 2025
PHP min version5.6
Downloads256K

Community Trust

Rating100/100
Number of ratings42
Active installs4K
Developer Profile

Marker.io – Visual Website Feedback Developer Profile

Marker.io

1 plugin · 4K total installs

87
trust score
Avg Security Score
99/100
Avg Patch Time
60 days
View full developer profile
Detection Fingerprints

How We Detect Marker.io – Visual Website Feedback

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/marker-io/markerio-icons.css/wp-content/plugins/marker-io/dist/styles.css/wp-content/plugins/marker-io/dist/scripts.js
Script Paths
/wp-content/plugins/marker-io/dist/scripts.js
Version Parameters
markerio_style?ver=markerio_script?ver=

HTML / DOM Fingerprints

Data Attributes
id="app"
JS Globals
__MarkermarkerConfigmarkerioPluginOptionsmarkerioAvailableUserRolesmarkerioAvailablePostTypesmarkerioCanMa
FAQ

Frequently Asked Questions about Marker.io – Visual Website Feedback