
Poll Directory Security & Risk Analysis
wordpress.org/plugins/poll-directoryThis plugin allows you to display a random pre-made poll. Choose a topic - we do the rest. A great sidebar widget to add fresh content.
Is Poll Directory Safe to Use in 2026?
Generally Safe
Score 85/100Poll Directory has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of "poll-directory" v2.1.0 reveals a plugin with a seemingly minimal attack surface and no recorded vulnerabilities. The absence of AJAX handlers, REST API routes, shortcodes, cron events, and file operations is a positive sign, indicating fewer potential entry points for attackers. Furthermore, the code's use of prepared statements for all SQL queries and the presence of capability checks are good security practices.
However, concerns arise from the limited output escaping, with only 20% of outputs being properly escaped. This could potentially lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not consistently sanitized before being displayed. The single external HTTP request also warrants investigation to ensure it's not susceptible to vulnerabilities like SSRF or man-in-the-middle attacks. The lack of nonce checks on any identified entry points (though there are none in this analysis) is a weakness that could be exploited if entry points were to be introduced in future versions or if the current analysis missed subtle entry points.
The complete absence of known CVEs and a vulnerability history is a strong indicator of good past security. This suggests the developers have either been diligent in addressing past issues or the plugin has not been a significant target. However, this also means there's less historical data to confirm long-term security robustness. Overall, while the plugin exhibits several good security practices and a clean vulnerability record, the low percentage of properly escaped output presents a notable risk that requires attention.
Key Concerns
- Low output escaping percentage
- External HTTP request without clear sanitization
- No nonce checks on potential entry points
Poll Directory Security Vulnerabilities
Poll Directory Code Analysis
Output Escaping
Poll Directory Attack Surface
WordPress Hooks 2
Maintenance & Trust
Poll Directory Maintenance & Trust
Maintenance Signals
Community Trust
Poll Directory Alternatives
No alternatives data available yet.
Poll Directory Developer Profile
5 plugins · 40 total installs
How We Detect Poll Directory
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/poll-directory/style.css/wp-content/plugins/poll-directory/script.jshttp://www.holypoll.com/poll/hp.jsHTML / DOM Fingerprints
dpmWidgetWrapperhpWidgetWrapperdpmZonedpmZoneDisplayAllhpZone<div class="hpWidgetWrapper" hpZone="">Loading poll from <a href="http://www.holypoll.com">HolyPoll</a> and the <a href="http://www.dimbal.com">Dimbal Poll Manager</a>.</div><script id="hpScript" src="http://www.holypoll.com/poll/hp.js" type="text/javascript"></script>