
Product Feature Request Security & Risk Analysis
wordpress.org/plugins/product-feature-requestProduct Feature Request plugin allows you to easily create and manage feature requests in your WordPress products.
Is Product Feature Request Safe to Use in 2026?
Generally Safe
Score 92/100Product Feature Request has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The product-feature-request plugin v1.2.3 exhibits a concerning security posture due to a significant number of unprotected AJAX handlers. While the plugin demonstrates good practices in other areas, such as using prepared statements for all SQL queries and having no recorded vulnerabilities, the lack of authentication checks on its entry points presents a substantial risk.
The static analysis revealed 4 AJAX handlers, all of which are exposed without any authentication or capability checks. This means any unauthenticated user could potentially trigger these handlers, leading to unintended actions or data manipulation. Although taint analysis did not identify critical or high-severity unsanitized flows, the presence of one unsanitized path flow is a red flag, especially when coupled with unprotected AJAX actions.
The absence of any known CVEs or past vulnerabilities is a positive indicator, suggesting a history of responsible development or simply a lack of targeted attacks. However, this does not negate the immediate risks posed by the unprotected AJAX endpoints. The plugin's strengths lie in its secure database interactions and file operations. The primary weakness is the broad attack surface created by insecure AJAX handlers, which overshadows its otherwise decent security practices.
Key Concerns
- Unprotected AJAX handlers
- Unsanitized path flow
- Limited capability checks
Product Feature Request Security Vulnerabilities
Product Feature Request Code Analysis
Output Escaping
Data Flow Analysis
Product Feature Request Attack Surface
AJAX Handlers 4
WordPress Hooks 14
Maintenance & Trust
Product Feature Request Maintenance & Trust
Maintenance Signals
Community Trust
Product Feature Request Alternatives
IdeaPush
ideapush
IdeaPush is a feature request management system for WordPress
FeedHub – Feedback Widget
feedhub-feedback-widget
Easily collect user feedback on your WordPress site with FeedHub's beautiful feedback widget.
RIACO Feedback
riaco-feedback
RIACO Feedback allows users to submit feature requests or feedback, vote on existing suggestions, and manage them via the WordPress admin.
Product Feature Request Developer Profile
16 plugins · 579K total installs
How We Detect Product Feature Request
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/product-feature-request/assets/public/css/thpfr-public.css/wp-content/plugins/product-feature-request/assets/public/js/thpfr-public.js/wp-content/plugins/product-feature-request/assets/admin/css/thpfr-admin.css/wp-content/plugins/product-feature-request/assets/admin/js/thpfr-admin.js/wp-content/plugins/product-feature-request/assets/public/js/thpfr-public.js/wp-content/plugins/product-feature-request/assets/admin/js/thpfr-admin.jsproduct-feature-request/assets/public/css/thpfr-public.css?ver=product-feature-request/assets/public/js/thpfr-public.js?ver=product-feature-request/assets/admin/css/thpfr-admin.css?ver=product-feature-request/assets/admin/js/thpfr-admin.js?ver=HTML / DOM Fingerprints
thpfr-admin-style<!-- Product Feature Request Settings --><!-- Save feature request data --><!-- Feature Request Custom Field Meta Box --><!-- End Feature Request Custom Field Meta Box -->data-product_iddata-request_iddata-targetdata-request-idTHPFR_ASSETS_URL_PUBLICTHPFR_ASSETS_URL_ADMINTHPFR_VERSIONTHPFR_AJAX_URL