Mopinion Feedback Form Security & Risk Analysis

wordpress.org/plugins/mopinion-feedback-form

Easy add feedback buttons and feedback forms to your website with the Mopinion.com Wordpress Plugin. Easy install, fast user insights.

100 active installs v1.1.1 PHP + WP 3.9+ Updated Dec 14, 2020
customer-feedbackscreenshot-feedbackuser-feedbackvisual-feedbackwebsite-feedback
63
C · Use Caution
CVEs total1
Unpatched1
Last CVEJan 27, 2026
Safety Verdict

Is Mopinion Feedback Form Safe to Use in 2026?

Use With Caution

Score 63/100

Mopinion Feedback Form has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Jan 27, 2026Updated 5yr ago
Risk Assessment

The "mopinion-feedback-form" plugin v1.1.1 presents a mixed security posture. On the positive side, the static analysis indicates a seemingly small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events, and crucially, no unprotected entry points. The code also shows good practices regarding SQL queries, with 100% using prepared statements, and no file operations or external HTTP requests are noted.

However, several significant concerns emerge. The taint analysis reveals a flow with unsanitized paths, which is a critical weakness even if no specific exploit was identified in this analysis. Furthermore, only 14% of output escaping is properly handled, leaving a substantial portion vulnerable to cross-site scripting (XSS) attacks. The complete absence of nonce and capability checks, despite the presence of output escaping issues, is particularly worrying, as these are fundamental security mechanisms. The vulnerability history highlights a known medium-severity XSS vulnerability that remains unpatched, indicating a recurring issue with input neutralization.

In conclusion, while the plugin has some strengths in its minimal attack surface and SQL practices, the presence of unsanitized paths, poor output escaping, lack of critical security checks (nonce, capability), and an unpatched historical vulnerability significantly elevate the risk. The plugin requires immediate attention to address these identified weaknesses.

Key Concerns

  • Unpatched CVE present
  • Unsanitized paths found in taint analysis
  • Low percentage of properly escaped output
  • No nonce checks
  • No capability checks
Vulnerabilities
1

Mopinion Feedback Form Security Vulnerabilities

CVEs by Year

1 CVE in 2026 · unpatched
2026
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-68856medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Mopinion Feedback Form <= 1.1.1 - Reflected Cross-Site Scripting

Jan 27, 2026Unpatched
Code Analysis
Analyzed Mar 16, 2026

Mopinion Feedback Form Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
25
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

14% escaped29 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<mopinion-feedback-form-admin-display> (admin\partials\mopinion-feedback-form-admin-display.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Mopinion Feedback Form Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionplugins_loadedincludes\class-mopinion-feedback-form.php:146
actionadmin_enqueue_scriptsincludes\class-mopinion-feedback-form.php:161
actionadmin_enqueue_scriptsincludes\class-mopinion-feedback-form.php:162
actionadmin_menuincludes\class-mopinion-feedback-form.php:165
actionadmin_initincludes\class-mopinion-feedback-form.php:168
actionwp_footerincludes\class-mopinion-feedback-form.php:187
Maintenance & Trust

Mopinion Feedback Form Maintenance & Trust

Maintenance Signals

WordPress version tested5.6.17
Last updatedDec 14, 2020
PHP min version
Downloads9K

Community Trust

Rating82/100
Number of ratings12
Active installs100
Developer Profile

Mopinion Feedback Form Developer Profile

keeswolters

1 plugin · 100 total installs

68
trust score
Avg Security Score
63/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Mopinion Feedback Form

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mopinion-feedback-form/admin/assets/css/countrySelect.css/wp-content/plugins/mopinion-feedback-form/admin/assets/css/mopinion-feedback-form-admin.css/wp-content/plugins/mopinion-feedback-form/admin/assets/js/mopinion-feedback-form-admin.js/wp-content/plugins/mopinion-feedback-form/admin/assets/js/countrySelect.min.js
Script Paths
/wp-content/plugins/mopinion-feedback-form/admin/assets/js/mopinion-feedback-form-admin.js/wp-content/plugins/mopinion-feedback-form/admin/assets/js/countrySelect.min.js
Version Parameters
mopinion-feedback-form/assets/css/countrySelect.css?ver=mopinion-feedback-form/assets/css/mopinion-feedback-form-admin.css?ver=mopinion-feedback-form/assets/js/mopinion-feedback-form-admin.js?ver=mopinion-feedback-form/assets/js/countrySelect.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
mopinion-feedback-form-admin
HTML Comments
<!-- Mopinion Feedback Form Settings --><!-- General -->
Data Attributes
data-plugin-namedata-plugin-version
JS Globals
mopinionFeedbackFormAdminmopinionApiHandler
FAQ

Frequently Asked Questions about Mopinion Feedback Form