
Pro Polls Security & Risk Analysis
wordpress.org/plugins/pro-pollsCreate polls with multiple questions and add to any page/posts.
Is Pro Polls Safe to Use in 2026?
Generally Safe
Score 85/100Pro Polls has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "pro-polls" v1.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices in its handling of SQL queries, exclusively using prepared statements, and the absence of file operations and external HTTP requests reduces certain attack vectors. The plugin also incorporates nonce and capability checks, which are essential for secure WordPress development.
However, significant concerns arise from the static analysis. The presence of the `unserialize` function is a critical red flag, as it can lead to Remote Code Execution vulnerabilities if not handled with extreme caution and proper sanitization. Furthermore, the taint analysis reveals a high number of flows with unsanitized paths (4 out of 5 analyzed), with all of them being of high severity. This strongly suggests that user-supplied data is not being adequately validated or escaped before being processed, potentially allowing attackers to inject malicious code or manipulate plugin behavior.
The plugin's vulnerability history is currently clean, with no recorded CVEs. While this is a positive indicator, it's important to remember that a clean history doesn't guarantee future safety, especially given the identified code-level weaknesses. The combination of dangerous functions and high-severity unsanitized taint flows points to a substantial risk of exploitable vulnerabilities within the plugin's current state.
Key Concerns
- High severity unsanitized taint flows
- Presence of dangerous unserialize function
- Low percentage of properly escaped output
Pro Polls Security Vulnerabilities
Pro Polls Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Pro Polls Attack Surface
Shortcodes 1
WordPress Hooks 8
Maintenance & Trust
Pro Polls Maintenance & Trust
Maintenance Signals
Community Trust
Pro Polls Alternatives
DOT | Monetize Polls & Quizzes
dot-monetize-polls-quizzes
The easiest way to create and publish interactive polls and quizzes from the Dot Platform. Fully integrated monetization and analytics.
VIZE Tests – Basic
vize-tests-basic
This plugin will help you to create and configure different type of tests with multiple choice questions. And embed those tests in any Post or Page us …
Crowdsignal Forms
crowdsignal-forms
The Crowdsignal Forms plugin allows you to create and manage polls right from within the block editor.
Crowdsignal Dashboard – Polls, Surveys & more
polldaddy
Manage your Crowdsignal polls, surveys, quizzes, and ratings directly from the WordPress dashboard.
Interactive Content – H5P
h5p
Create and add rich content to your website for free. Some examples of what you get with H5P are Interactive Video, Quizzes, Collage and Timeline.
Pro Polls Developer Profile
1 plugin · 10 total installs
How We Detect Pro Polls
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pro-polls/themes/pro-polls.cssHTML / DOM Fingerprints
button-errorpoll_id[pro_polls]