
Pollfish for WordPress Security & Risk Analysis
wordpress.org/plugins/pollfish-for-wpThe Pollfish for WordPress plugin enables you to add PollFish Surveys to your WordPress website and Monetize it easily.
Is Pollfish for WordPress Safe to Use in 2026?
Generally Safe
Score 85/100Pollfish for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "pollfish-for-wp" plugin version 1.1.0 demonstrates a generally good security posture based on the provided static analysis. The limited attack surface, with only one AJAX handler and no unprotected entry points, is a positive indicator. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests further strengthens its security. The use of prepared statements for SQL queries and the presence of a nonce check are also commendable security practices.
However, a significant concern arises from the output escaping. With 52% of outputs not being properly escaped, there is a notable risk of Cross-Site Scripting (XSS) vulnerabilities. This means that user-supplied data could potentially be injected and executed as malicious JavaScript within the WordPress admin area or on the front-end, depending on where these outputs are displayed. The lack of capability checks is also a weakness, as it doesn't explicitly verify user permissions before performing actions via the AJAX handler.
The plugin's vulnerability history is clean, with no recorded CVEs. This, coupled with the absence of critical or high-severity taint flows, suggests that past versions have also maintained a good security record. This history, combined with the current code analysis, indicates a developer who is likely attentive to security, but has overlooked a critical aspect of output sanitization.
Key Concerns
- Insufficient output escaping
- Missing capability checks
Pollfish for WordPress Security Vulnerabilities
Pollfish for WordPress Code Analysis
Output Escaping
Data Flow Analysis
Pollfish for WordPress Attack Surface
AJAX Handlers 1
WordPress Hooks 10
Maintenance & Trust
Pollfish for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Pollfish for WordPress Alternatives
UserFeedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds
userfeedback-lite
Ultimate user feedback plugin to ask questions, surveys, polls, from your website in seconds
Crowdsignal Forms
crowdsignal-forms
The Crowdsignal Forms plugin allows you to create and manage polls right from within the block editor.
Crowdsignal Dashboard – Polls, Surveys & more
polldaddy
Manage your Crowdsignal polls, surveys, quizzes, and ratings directly from the WordPress dashboard.
TrustMate.io – WooCommerce integration
trustmate-io-integration-for-woocommerce
TrustMate - Reviews for your shop and products at you WooCommerce site. Generate valuable traffic and profit more than others!
FeedFocal
feedfocal
Collect user feedback with our easy to use survey tools! Create surveys in seconds.
Pollfish for WordPress Developer Profile
2 plugins · 1K total installs
How We Detect Pollfish for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pollfish-for-wp/js/pollfish-for-wordpress-public.js/wp-content/plugins/pollfish-for-wp/css/pollfish-for-wordpress-public.css/wp-content/plugins/pollfish-for-wp/js/pollfish-for-wordpress-public.jspollfish-for-wp/js/pollfish-for-wordpress-public.js?ver=pollfish-for-wp/css/pollfish-for-wordpress-public.css?ver=HTML / DOM Fingerprints
<!-- This file is the main plugin file -->data-pollfish-api-keydata-pollfish-secret-keyPollfish