Pinpoll Security & Risk Analysis

wordpress.org/plugins/pinpoll

Engage with your audience.

40 active installs v4.0.0 PHP + WP 3.3.0+ Updated Unknown
analyticsfeedbackmarketingpollsurvey
78
B · Generally Safe
CVEs total1
Unpatched1
Last CVEDec 30, 2025
Safety Verdict

Is Pinpoll Safe to Use in 2026?

Mostly Safe

Score 78/100

Pinpoll is generally safe to use. 1 past CVE were resolved. Keep it updated.

1 known CVE 1 unpatched Last CVE: Dec 30, 2025
Risk Assessment
Assessment pending
Vulnerabilities
1

Pinpoll Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-68889medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Pinpoll <= 4.0.0 - Reflected Cross-Site Scripting

Dec 30, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Pinpoll Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
19
30 escaped
Nonce Checks
4
Capability Checks
0
File Operations
0
External Requests
12
Bundled Libraries
1

Bundled Libraries

TinyMCE

SQL Query Safety

100% prepared4 total queries

Output Escaping

61% escaped49 total outputs
Data Flows
6 unsanitized

Data Flow Analysis

6 flows6 with unsanitized paths
search_box (admin\includes\class-wp-list-table.php:346)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Pinpoll Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[pinpoll] pinpoll.php:56
WordPress Hooks 4
actionadmin_footeradmin\includes\class-wp-list-table.php:157
actionwp_loadedadmin\pinpoll-account-status.php:43
actionadmin_initpinpoll.php:55
actioninitpinpoll.php:61
Maintenance & Trust

Pinpoll Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedUnknown
PHP min version
Downloads11K

Community Trust

Rating96/100
Number of ratings10
Active installs40
Developer Profile

Pinpoll Developer Profile

Pinpoll

1 plugin · 40 total installs

79
trust score
Avg Security Score
78/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Pinpoll

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/pinpoll/admin/css/pinpoll.css/wp-content/plugins/pinpoll/admin/js/pinpoll.js
Script Paths
/wp-content/plugins/pinpoll/admin/js/pinpoll.js
Version Parameters
pinpoll/admin/css/pinpoll.css?ver=pinpoll/admin/js/pinpoll.js?ver=

HTML / DOM Fingerprints

CSS Classes
pinpoll-admin
Data Attributes
data-pinpoll-id
JS Globals
pinpoll_admin
Shortcode Output
wp_oembed_get( PINPOLL_URL.'/embed/'
FAQ

Frequently Asked Questions about Pinpoll