
PageProofer Security & Risk Analysis
wordpress.org/plugins/pageprooferAllow developers, designers, clients and site visitors to easily leave feedback directly on your website.
Is PageProofer Safe to Use in 2026?
Generally Safe
Score 100/100PageProofer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of PageProofer v1.4.0 reveals a generally strong security posture with no identified attack surface through AJAX, REST API, shortcodes, or cron events. The absence of dangerous functions and reliance on prepared statements for SQL queries are positive indicators of secure coding practices. However, the analysis flags a significant concern regarding output escaping, with 100% of identified outputs being unescaped. This means that any data rendered by the plugin could potentially be vulnerable to cross-site scripting (XSS) attacks if user-supplied input is not properly sanitized before display.
The vulnerability history for PageProofer is clean, with no recorded CVEs. This suggests a good track record of security over time, potentially indicating diligent patching or robust development practices in the past. The lack of taint analysis results, while seemingly positive, could also be due to the limited attack surface analyzed or the absence of detectable taint flows within the analyzed code. The overall conclusion is that while the plugin exhibits good practices in terms of attack surface management and database interaction, the unescaped output represents a critical security weakness that needs immediate attention.
Key Concerns
- All identified outputs are unescaped.
PageProofer Security Vulnerabilities
PageProofer Code Analysis
Output Escaping
PageProofer Attack Surface
WordPress Hooks 6
Maintenance & Trust
PageProofer Maintenance & Trust
Maintenance Signals
Community Trust
PageProofer Alternatives
Marker.io – Visual Website Feedback
marker-io
Collect visual website feedback from colleagues and clients on your WordPress site.
Feedbucket – Website Feedback Tool
feedbucket
Enable your clients and team members to submit feedback using screenshot and recordings on your WordPress site.
Superflow: Markup live websites
superflow
Comment and collaborate directly on your live Wordpress website.
Ybug Feedback Widget
ybug-feedback-widget
Collect visual feedback and bug reports with screenshots from your users. This plugin allows you to easily add Ybug Feedback Widget on your website.
Webvizio
webvizio
The Ultimate Visual Feedback, Collaboration & Productivity Tool for Web Professionals.
PageProofer Developer Profile
1 plugin · 50 total installs
How We Detect PageProofer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pageproofer/css/pageproofer-admin.css/wp-content/plugins/pageproofer/js/pageproofer-admin.js/wp-content/plugins/pageproofer/js/pageproofer-admin.jspageproofer/css/pageproofer-admin.css?ver=pageproofer/js/pageproofer-admin.js?ver=HTML / DOM Fingerprints
name='pageproofer_settings[pageproofer_site_key]'name='pageproofer_settings[pageproofer_enabled]'