
Poll And Vote System Security & Risk Analysis
wordpress.org/plugins/poll-and-vote-systemPoll system in WordPress block enabled. Add a poll to post throw shortcode and get all poll throw rest API.
Is Poll And Vote System Safe to Use in 2026?
Generally Safe
Score 85/100Poll And Vote System has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The security posture of the "poll-and-vote-system" v1.0.0 plugin presents significant concerns primarily due to its exposed attack surface and the handling of SQL queries. While the plugin exhibits some positive attributes, such as a lack of critical or high severity vulnerabilities in its history and a good rate of output escaping, the number of unprotected AJAX handlers is a major red flag. The absence of authentication checks on seven AJAX endpoints creates a broad entry point for potential attackers to exploit. Furthermore, the fact that 100% of the SQL queries are not using prepared statements is a critical weakness that could easily lead to SQL injection vulnerabilities, especially when combined with the unprotected AJAX handlers. The taint analysis revealing two flows with unsanitized paths further exacerbates these risks, suggesting that untrusted input might be directly used in sensitive operations without proper validation or sanitization. Although the plugin has no recorded historical vulnerabilities and a decent output escaping rate, these are overshadowed by the present, demonstrable weaknesses in its current implementation. A balanced conclusion suggests that while the plugin is not historically problematic, its current design has significant exploitable flaws that require immediate attention.
Key Concerns
- AJAX handlers without auth checks
- SQL queries not using prepared statements
- Taint flows with unsanitized paths (High Severity)
- Total entry points: 8, Unprotected: 7
- Nonce checks present but not universally applied
- Capability checks present but not universally applied
Poll And Vote System Security Vulnerabilities
Poll And Vote System Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Poll And Vote System Attack Surface
AJAX Handlers 7
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
Poll And Vote System Maintenance & Trust
Maintenance Signals
Community Trust
Poll And Vote System Alternatives
WP-Polls
wp-polls
Adds an AJAX poll system to your WordPress blog. You can also easily add a poll into your WordPress's blog post/page.
Pollify – Feedback Polls, Anonymous Polls, Up/down Voting, NPS Surveys, Export data
poll-creator
Poll creator lets you create a poll website in WordPress Gutenberg with advanced polling/voting features to engage your audience like never before
WP EASY POLL
wp-easy-poll
With WP EASY POLL user could add ajax based voting poll system to wordpress driven sites very easily.
WP-Polls (with CubePoints)
wp-polls-with-cubepoints
WP-Polls (with CubePoints) is a modified version of [WP-Polls](http://wordpress.org/extend/plugins/wp-polls/ "WP-Polls") by Lester 'GaM …
Crowdsignal Dashboard – Polls, Surveys & more
polldaddy
Manage your Crowdsignal polls, surveys, quizzes, and ratings directly from the WordPress dashboard.
Poll And Vote System Developer Profile
2 plugins · 4K total installs
How We Detect Poll And Vote System
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/poll-and-vote-system/css/bootstrap.css/wp-content/plugins/poll-and-vote-system/css/pvs-poll.css/wp-content/plugins/poll-and-vote-system/build/pvs-block.js/wp-content/plugins/poll-and-vote-system/js/pvs-poll.js/wp-content/plugins/poll-and-vote-system/js/pvs-poll-dashboard.jsbuild/pvs-block.jsjs/pvs-poll.jsjs/pvs-poll-dashboard.jspoll-and-vote-system/css/bootstrap.css?ver=poll-and-vote-system/css/pvs-poll.css?ver=poll-and-vote-system/build/pvs-block.js?ver=poll-and-vote-system/js/pvs-poll.js?ver=poll-and-vote-system/js/pvs-poll-dashboard.js?ver=HTML / DOM Fingerprints
pvs-poll-answer-optionspvs-poll-question-wrapperpvs-poll-vote-button<!-- End of PVS Poll Plugin -->data-poll-iddata-answer-idpvs_blockpvs/wp-json/pvs-poll/v1/votes[pvs_poll]