
Orbisius Simple Feedback Security & Risk Analysis
wordpress.org/plugins/orbisius-simple-feedbackGenerates a nice & simple Feedback form which is positioned at the bottom center of your visitor's browser window.
Is Orbisius Simple Feedback Safe to Use in 2026?
Generally Safe
Score 85/100Orbisius Simple Feedback has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'orbisius-simple-feedback' plugin v1.0.8 presents a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for its single SQL query and avoids file operations and external HTTP requests. The absence of any recorded vulnerabilities in its history is also a strong indicator of a well-maintained codebase. However, significant concerns arise from the static analysis. The plugin exposes two AJAX handlers, both of which lack any authentication or authorization checks, creating a substantial attack surface for potential unauthorized actions. Furthermore, a concerning 80% of its output is not properly escaped, leaving it vulnerable to cross-site scripting (XSS) attacks when displaying user-generated or dynamic content. The lack of nonce checks on these AJAX endpoints exacerbates the risk by making it easier for attackers to craft malicious requests.
Key Concerns
- AJAX handlers without authorization checks
- Significant portion of output not properly escaped
- Missing nonce checks on AJAX handlers
Orbisius Simple Feedback Security Vulnerabilities
Orbisius Simple Feedback Release Timeline
Orbisius Simple Feedback Code Analysis
SQL Query Safety
Output Escaping
Orbisius Simple Feedback Attack Surface
AJAX Handlers 2
WordPress Hooks 9
Maintenance & Trust
Orbisius Simple Feedback Maintenance & Trust
Maintenance Signals
Community Trust
Orbisius Simple Feedback Alternatives
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder
fluentform
Get a fast contact form plugin. Create advanced forms using drag and drop form builder with all smart features.
Database Addon for Contact Form 7 – CFDB7
contact-form-cfdb7
Save and manage Contact Form 7 messages. Never lose important data. It is a lightweight contact form 7 database plugin.
Image CAPTCHA for Contact Form 7 and WPForms by HookAndHook (DSGVO/GDPR)
contact-form-7-image-captcha
Adds an Image CAPTCHA to Contact Form 7 and WPForms, GDPR ready, perfect WPForms or Contact Form 7 Spam Protection Image CAPTCHA, adds a honeypot
Database for Contact Form 7, WPforms, Elementor forms
contact-form-entries
Saves Contact Form 7, WPforms,Elementor Forms, CRM Perks Forms and many other contact form submissions to database.
Buttonizer – Live Chat, AI Chatbot, Call, Chat, Contact Button
button-contact-vr
Powerful platform with Live Chat, AI Chatbots, and Real-Time Visitor Monitoring! Also, create Call, Email, SMS, & Contact buttons to increase conv …
Orbisius Simple Feedback Developer Profile
28 plugins · 12K total installs
How We Detect Orbisius Simple Feedback
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/orbisius-simple-feedback/assets/main.css/wp-content/plugins/orbisius-simple-feedback/assets/main.min.css/wp-content/plugins/orbisius-simple-feedback/assets/main.js/wp-content/plugins/orbisius-simple-feedback/assets/main.min.js/wp-content/plugins/orbisius-simple-feedback/assets/main.js/wp-content/plugins/orbisius-simple-feedback/assets/main.min.jsorbisius-simple-feedback/assets/main.css?ver=orbisius-simple-feedback/assets/main.min.css?ver=orbisius-simple-feedback/assets/main.js?ver=orbisius-simple-feedback/assets/main.min.js?ver=HTML / DOM Fingerprints
orbisius_simple_feedback_containerfeedback_wrapperfeedback_wrapper_shortfeedback_wrapper_leftfeedback_wrapper_rightfeedback_title_wrappfeedback_textpowered_by<!-- Orbisius Simple Feedback | http://club.orbisius.com/products/wordpress-plugins/orbisius-simple-feedback/ : is disabled or it's an ajax request. Skipping rendering. -->orbisius_simple_feedback_container_cfgorbisius_simple_feedback_configorbisius_simple_feedback_container_cfg