
PollMe Security & Risk Analysis
wordpress.org/plugins/pollmeAn easy to modify poll system that uses Google Charts to display the results
Is PollMe Safe to Use in 2026?
Generally Safe
Score 85/100PollMe has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "pollme" plugin version 4.5.46 exhibits a mixed security posture. On the positive side, it has a very small attack surface with zero identified entry points for direct exploitation. Furthermore, all SQL queries are properly parameterized, and there is no recorded vulnerability history, suggesting a mature and stable codebase. However, significant concerns arise from the static analysis. The plugin utilizes dangerous functions like `set_time_limit` and `unserialize`, which can be misused to impact server performance or execute arbitrary code if user input is not strictly controlled. The lack of any nonce checks or capability checks on potential entry points, coupled with a concerningly low percentage of properly escaped output (only 37%), presents a substantial risk. This indicates that user-supplied data could be injected into the application or the browser without proper sanitization, leading to cross-site scripting (XSS) or other injection vulnerabilities. Taint analysis, while showing no critical or high severity flows, did identify three flows with unsanitized paths, reinforcing the output escaping concerns.
Key Concerns
- Missing nonce checks on entry points
- Missing capability checks on entry points
- Low percentage of properly escaped output
- Use of unserialize function
- Use of set_time_limit function
- Taint flows with unsanitized paths
PollMe Security Vulnerabilities
PollMe Release Timeline
PollMe Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
PollMe Attack Surface
WordPress Hooks 2
Maintenance & Trust
PollMe Maintenance & Trust
Maintenance Signals
Community Trust
PollMe Alternatives
QuizMe
quizme
An easy to modify quiz system
Spam protection, Honeypot, Anti-Spam by CleanTalk
cleantalk-spam-protect
Blocks spam comments, fake users, contact form spam and more. No impact on SEO. Privacy focused. CAPTCHA free, premium Antispam plugin.
Crowdsignal Forms
crowdsignal-forms
The Crowdsignal Forms plugin allows you to create and manage polls right from within the block editor.
ReCaptcha v2 for Contact Form 7
wpcf7-recaptcha
Adds reCaptcha v2 from Contact Form 7 5.0.5 that was dropped on Contact Form 7 5.1
Contact Form 7 Captcha
contact-form-7-simple-recaptcha
Protect your Contact Form 7 forms with Google reCAPTCHA V2, Google reCAPTCHA V3, hCAPTCHA, or Cloudflare Turnstile.
PollMe Developer Profile
6 plugins · 60 total installs
How We Detect PollMe
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pollme/library/base/public/css/images.css/wp-content/plugins/pollme/library/base/public/css/admin.css/wp-content/plugins/pollme/library/base/public/css/front.css/wp-content/plugins/pollme/library/base/public/css/common.css/wp-content/plugins/pollme/library/base/public/js/script.js/wp-content/plugins/pollme/library/base/public/js/script.jspollme/library/base/public/css/images.css?ver=pollme/library/base/public/css/admin.css?ver=pollme/library/base/public/css/front.css?ver=pollme/library/base/public/css/common.css?ver=pollme/library/base/public/js/script.js?ver=HTML / DOM Fingerprints
pollmepollme-wrapperpollme-questionpollme-answerspollme-answer-itempollme-resultsdata-pollme-idv46v_data/wp-json/pollme/[pollme]