
My Simple Feedback Security & Risk Analysis
wordpress.org/plugins/my-simple-feedbackThe plugin
Is My Simple Feedback Safe to Use in 2026?
Generally Safe
Score 85/100My Simple Feedback has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "my-simple-feedback" plugin v1.0 demonstrates a strong adherence to secure coding practices based on the provided static analysis. The absence of any detected AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the potential attack surface. Furthermore, the code signals indicate a clean bill of health in terms of dangerous functions, raw SQL queries (all prepared statements), file operations, and external HTTP requests. The lack of any taint analysis findings and zero known vulnerabilities in its history further bolster its security posture.
However, the static analysis does raise a concern regarding output escaping, with only 51% of outputs being properly escaped. While not immediately indicative of a critical vulnerability without further context, this partial escaping could potentially lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is involved in the unescaped outputs. The complete absence of nonce checks and capability checks, while seemingly safe due to the lack of direct entry points, means that if any entry points were to be introduced in future versions or through misconfiguration, these critical security layers would be missing.
In conclusion, the plugin currently presents a very low security risk due to its minimal attack surface and clean vulnerability history. The primary area for improvement lies in ensuring all output is properly escaped to mitigate potential XSS risks. The lack of authentication and nonce checks on its non-existent entry points is not a direct risk at this moment but represents a potential weakness that could be exploited if the plugin's functionality evolves.
Key Concerns
- Partially unescaped output detected
- Missing nonce checks
- Missing capability checks
My Simple Feedback Security Vulnerabilities
My Simple Feedback Release Timeline
My Simple Feedback Code Analysis
Output Escaping
My Simple Feedback Attack Surface
WordPress Hooks 4
Maintenance & Trust
My Simple Feedback Maintenance & Trust
Maintenance Signals
Community Trust
My Simple Feedback Alternatives
Contact Form & SMTP Plugin for WordPress by PirateForms
pirate-forms
A simple and effective WordPress contact form & SMTP plugin. Compatible with best themes out there, is both a secure and responsive contact form p …
Contact Form Clean and Simple
clean-and-simple-contact-form-by-meg-nicholas
A clean and simple contact form with flexible CSS framework support.
Survey Maker
survey-maker
Create free online surveys and get your visitors' feedbacks directly on your WordPress website with WordPress Survey Plugin
Popups – Submission Messages For Contact Form 7
cf7-popups
Display contact form 7 default messages in stylish popup as user submits the form.
CF7 Submissions – Securely Store Contact Form 7 Data and Attachments, Reply to the Sender and more
cf7-submissions
Securely Store and Manage CF7 Submissions Hassle-Free
My Simple Feedback Developer Profile
9 plugins · 40 total installs
How We Detect My Simple Feedback
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/my-simple-feedback/library/plance/validate.js/wp-content/plugins/my-simple-feedback/library/plance/request.js/wp-content/plugins/my-simple-feedback/library/plance/view.js/wp-content/plugins/my-simple-feedback/library/wp-plance/flash.js/wp-content/plugins/my-simple-feedback/library/plance/validate.js/wp-content/plugins/my-simple-feedback/library/plance/request.js/wp-content/plugins/my-simple-feedback/library/plance/view.js/wp-content/plugins/my-simple-feedback/library/wp-plance/flash.jsHTML / DOM Fingerprints
plance-sfb-formr-namer-emailr-subjectr-messager-isdata-validate="true"window.Plance_SFB_Index_INIT[plance_simple_feedback]