
Polling by Alex Lundin Security & Risk Analysis
wordpress.org/plugins/polling-by-alex-lundinPlugin for creating surveys about a single product, product, service.
Is Polling by Alex Lundin Safe to Use in 2026?
Generally Safe
Score 85/100Polling by Alex Lundin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "polling-by-alex-lundin" plugin v1.0.1 exhibits significant security concerns primarily due to a large, unprotected attack surface. While the plugin demonstrates good practices in output escaping and doesn't utilize dangerous functions or perform external HTTP requests, the lack of authentication and permission checks on all AJAX handlers and REST API routes presents a major risk. The static analysis reveals that 5 out of 5 identified entry points are unprotected, meaning any unauthenticated user could potentially interact with these functionalities.
The taint analysis further highlights this concern, identifying 3 high-severity flows with unsanitized paths. This suggests that user-supplied data might be used in a way that could lead to vulnerabilities like injection attacks if not properly handled within these unprotected entry points. The absence of nonce checks on AJAX handlers is a critical oversight that exacerbates the risk of Cross-Site Request Forgery (CSRF) attacks. The vulnerability history is clean, which is a positive indicator, but it does not mitigate the immediate risks identified in the code analysis, especially considering the absence of fundamental security controls.
In conclusion, the plugin has strengths in avoiding common pitfalls like dangerous functions and output escaping. However, the critical lack of authentication and authorization on its primary entry points (AJAX and REST API) combined with high-severity unsanitized taint flows creates a substantial security risk. The clean vulnerability history is a good sign but should not lead to complacency given the evident gaps in basic security implementation.
Key Concerns
- All AJAX handlers unprotected
- All REST API routes unprotected
- High severity unsanitized taint flows (3)
- No nonce checks on AJAX handlers
Polling by Alex Lundin Security Vulnerabilities
Polling by Alex Lundin Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Polling by Alex Lundin Attack Surface
AJAX Handlers 3
REST API Routes 2
WordPress Hooks 14
Maintenance & Trust
Polling by Alex Lundin Maintenance & Trust
Maintenance Signals
Community Trust
Polling by Alex Lundin Alternatives
Crowdsignal Forms
crowdsignal-forms
The Crowdsignal Forms plugin allows you to create and manage polls right from within the block editor.
Simply Polls
simply-polls
Add AJAX poll to your WordPress blog. You can use our polls on sidebars, posts and pages.
AI Vision Block
ai-vision-block
Generate AI images using Pollinations API directly from the WordPress block editor and save them to the Media Library.
Classic Editor
classic-editor
Enables the previous "classic" editor and the old-style Edit Post screen with TinyMCE, Meta Boxes, etc. Supports all plugins that extend this screen.
Starter Templates – AI-Powered Templates for Elementor & Gutenberg
astra-sites
The growing library of 300+ ready-to-use templates that work with all WordPress themes including Astra, Hello, OceanWP, GeneratePress and more
Polling by Alex Lundin Developer Profile
3 plugins · 10 total installs
How We Detect Polling by Alex Lundin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/polling-by-alex-lundin/assets/prod/css/admin.css/wp-content/plugins/polling-by-alex-lundin/assets/prod/js/manifest.js/wp-content/plugins/polling-by-alex-lundin/assets/prod/js/vendor.js/wp-content/plugins/polling-by-alex-lundin/assets/prod/js/admin.js/wp-content/plugins/polling-by-alex-lundin/assets/prod/js/manifest.js/wp-content/plugins/polling-by-alex-lundin/assets/prod/js/vendor.js/wp-content/plugins/polling-by-alex-lundin/assets/prod/js/admin.jspolling-by-alex-lundin/assets/prod/css/admin.css?ver=polling-by-alex-lundin/assets/prod/js/manifest.js?ver=polling-by-alex-lundin/assets/prod/js/vendor.js?ver=polling-by-alex-lundin/assets/prod/js/admin.js?ver=HTML / DOM Fingerprints
asl_polling_admin