Orbisius Simple Feedback Security & Risk Analysis

wordpress.org/plugins/orbisius-simple-feedback

Generates a nice & simple Feedback form which is positioned at the bottom center of your visitor's browser window.

10 active installs v1.0.8 PHP + WP 2.6+ Updated Feb 7, 2016
chatcontactfeedbackorbisiuswp
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Orbisius Simple Feedback Safe to Use in 2026?

Generally Safe

Score 85/100

Orbisius Simple Feedback has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The 'orbisius-simple-feedback' plugin v1.0.8 presents a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for its single SQL query and avoids file operations and external HTTP requests. The absence of any recorded vulnerabilities in its history is also a strong indicator of a well-maintained codebase. However, significant concerns arise from the static analysis. The plugin exposes two AJAX handlers, both of which lack any authentication or authorization checks, creating a substantial attack surface for potential unauthorized actions. Furthermore, a concerning 80% of its output is not properly escaped, leaving it vulnerable to cross-site scripting (XSS) attacks when displaying user-generated or dynamic content. The lack of nonce checks on these AJAX endpoints exacerbates the risk by making it easier for attackers to craft malicious requests.

Key Concerns

  • AJAX handlers without authorization checks
  • Significant portion of output not properly escaped
  • Missing nonce checks on AJAX handlers
Vulnerabilities
None known

Orbisius Simple Feedback Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Orbisius Simple Feedback Release Timeline

v1.0.8Current
v1.0.7
v1.0.6
v1.0.5
v1.0.4
v1.0.3
v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

Orbisius Simple Feedback Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
57
14 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

20% escaped71 total outputs
Attack Surface
2 unprotected

Orbisius Simple Feedback Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_orbisius_simple_feedback_ajaxorbisius-simple-feedback.php:36
noprivwp_ajax_orbisius_simple_feedback_ajaxorbisius-simple-feedback.php:37
WordPress Hooks 9
actioninitorbisius-simple-feedback.php:29
actionadmin_menuorbisius-simple-feedback.php:31
actionwp_headorbisius-simple-feedback.php:32
actionadmin_headorbisius-simple-feedback.php:33
actionwp_footerorbisius-simple-feedback.php:34
actionadmin_enqueue_scriptsorbisius-simple-feedback.php:92
actionadmin_footerorbisius-simple-feedback.php:93
filterplugin_action_linksorbisius-simple-feedback.php:324
actionadmin_initorbisius-simple-feedback.php:327
Maintenance & Trust

Orbisius Simple Feedback Maintenance & Trust

Maintenance Signals

WordPress version tested4.4.34
Last updatedFeb 7, 2016
PHP min version
Downloads4K

Community Trust

Rating100/100
Number of ratings3
Active installs10
Developer Profile

Orbisius Simple Feedback Developer Profile

Svetoslav Marinov

28 plugins · 12K total installs

69
trust score
Avg Security Score
86/100
Avg Patch Time
722 days
View full developer profile
Detection Fingerprints

How We Detect Orbisius Simple Feedback

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/orbisius-simple-feedback/assets/main.css/wp-content/plugins/orbisius-simple-feedback/assets/main.min.css/wp-content/plugins/orbisius-simple-feedback/assets/main.js/wp-content/plugins/orbisius-simple-feedback/assets/main.min.js
Script Paths
/wp-content/plugins/orbisius-simple-feedback/assets/main.js/wp-content/plugins/orbisius-simple-feedback/assets/main.min.js
Version Parameters
orbisius-simple-feedback/assets/main.css?ver=orbisius-simple-feedback/assets/main.min.css?ver=orbisius-simple-feedback/assets/main.js?ver=orbisius-simple-feedback/assets/main.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
orbisius_simple_feedback_containerfeedback_wrapperfeedback_wrapper_shortfeedback_wrapper_leftfeedback_wrapper_rightfeedback_title_wrappfeedback_textpowered_by
HTML Comments
<!-- Orbisius Simple Feedback | http://club.orbisius.com/products/wordpress-plugins/orbisius-simple-feedback/ : is disabled or it's an ajax request. Skipping rendering. -->
Data Attributes
orbisius_simple_feedback_container_cfg
JS Globals
orbisius_simple_feedback_configorbisius_simple_feedback_container_cfg
FAQ

Frequently Asked Questions about Orbisius Simple Feedback