
NPS computy Security & Risk Analysis
wordpress.org/plugins/nps-computyFree monitoring of the NPS (Net Promoter Score) index for your business.
Is NPS computy Safe to Use in 2026?
Generally Safe
Score 93/100NPS computy has a strong security track record. Known vulnerabilities have been patched promptly.
The "nps-computy" v2.8.4 plugin exhibits a mixed security posture. While it demonstrates some good practices, such as a low number of external HTTP requests and file operations, significant concerns remain. The presence of two AJAX handlers without authentication checks presents a direct attack vector, potentially allowing unauthorized users to trigger plugin functionality. Furthermore, the static analysis reveals that a substantial portion of SQL queries are not using prepared statements, increasing the risk of SQL injection vulnerabilities. The output escaping is also a concern, with a notable percentage of outputs not being properly escaped, which could lead to cross-site scripting vulnerabilities.
The plugin's vulnerability history is particularly alarming, with four known CVEs, including one high-severity and three medium-severity issues. The historical prevalence of Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerabilities suggests a recurring pattern of insecure coding practices related to input handling and state management. Although there are currently no unpatched vulnerabilities, the sheer number and types of past issues indicate a systemic weakness that needs addressing. The presence of an outdated bundled library (DataTables v1.10.21) also adds to the risk profile.
In conclusion, while the plugin avoids certain high-risk areas like critical taint flows or raw file operations, the combination of unprotected entry points, insecure SQL practices, insufficient output escaping, and a history of common and severe vulnerabilities points to a moderate to high overall security risk. Addressing the unprotected AJAX handlers, improving SQL sanitation, and ensuring proper output escaping are critical next steps to improve its security.
Key Concerns
- Unprotected AJAX handlers
- Significant portion of SQL queries not prepared
- Substantial percentage of outputs not escaped
- Bundled outdated library (DataTables v1.10.21)
- History of high-severity vulnerabilities (1)
- History of medium-severity vulnerabilities (3)
NPS computy Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
NPS computy <= 2.8.2 - Unauthenticated Stored Cross-Site Scripting
NPS computy <= 2.8.0 - Reflected Cross-Site Scripting
NPS computy <= 2.7.5 - Cross-Site Request Forgery to Results Deletion
NPS computy <= 2.7.5 - Authenticated (Admin+) Stored Cross-Site Scripting
NPS computy Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
NPS computy Attack Surface
AJAX Handlers 2
Shortcodes 2
WordPress Hooks 9
Maintenance & Trust
NPS computy Maintenance & Trust
Maintenance Signals
Community Trust
NPS computy Alternatives
NPS Monitoring
nps-monitoring
This plugin allows you to display a simple NPS Monitoring survey. Data is then calculated and analyzed to determine your Net Promoter Score.
SightMill Net Promoter Score (NPS) feedback surveys
sightmill-nps
Add SightMill.com Net Promoter Score (NPS) feedback surveys to your website
zenloop for WooCommerce – Net Promoter Score (NPS) platform
zenloop-woocommerce-nps-platform
zenloop for WooCommerce is the official zenloop.com plugin. It connects zenloop’s Net Promoter Score (NPS) platform with your WooCommerce shop.
FeedFocal
feedfocal
Collect user feedback with our easy to use survey tools! Create surveys in seconds.
Word Stats
word-stats
A suite of word counters, keyword counters and readability analysis for your blog.
NPS computy Developer Profile
6 plugins · 330 total installs
How We Detect NPS computy
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/nps-computy/_inc/nps-computy-style.css/wp-content/plugins/nps-computy/_inc/nps-computy-script.js/wp-content/plugins/nps-computy/_inc/nps-computy-script.jsnps-computy-style.css?ver=nps-computy-script.js?ver=HTML / DOM Fingerprints
npszagolovok-npsquestion-containerdesc-npsvalidationErrornps-radiosindexinput_nps+1 more<!--Общие переменные--><!--версия плагина--><!--Страница админки-->/*Страница админки*/+3 moreid="nps-computy"action="javascript:void(null);"nps_computy_scriptnps_computy_activatenps_computy_deactivateadd_nps_computy_stylesnps_func<div class="nps"><div class="zagolovok-nps"><div class="desc-nps"><div class="validationError"