Qualtrics Survey Embeds Security & Risk Analysis

wordpress.org/plugins/qualtrics-survey-embeds

Adds a Qualtrics Embed Handler to WordPress allowing for quick survey embeds.

100 active installs v1.0 PHP + WP 2.9.0+ Updated Aug 10, 2015
embedoembedqualtricssurveys
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Qualtrics Survey Embeds Safe to Use in 2026?

Generally Safe

Score 85/100

Qualtrics Survey Embeds has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The "qualtrics-survey-embeds" plugin v1.0 exhibits a generally good security posture based on the provided static analysis. It has no recorded CVEs, a clean vulnerability history, and the static analysis reveals no critical or high-severity issues in taint flows. Furthermore, it has zero identified AJAX handlers, REST API routes, shortcodes, or cron events, indicating a very small attack surface with no immediately apparent entry points. All identified SQL queries utilize prepared statements, and there are no file operations or external HTTP requests, which are positive indicators.

However, a significant concern arises from the output escaping. With 43 total outputs and only 35% properly escaped, there's a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. This lack of consistent output sanitization means that user-supplied data, if not handled carefully before being displayed, could be maliciously injected and executed in the user's browser. The absence of nonce and capability checks, while potentially mitigated by the lack of entry points, still represents a missed opportunity for robust security, especially if functionality were to be added or discovered later.

In conclusion, while the plugin's minimal attack surface and lack of historical vulnerabilities are strengths, the poor output escaping presents a clear and present danger. The vulnerability history shows no past issues, which is a positive sign, but the current code analysis highlights a critical weakness that needs immediate attention to prevent potential security breaches.

Key Concerns

  • Low output escaping percentage
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Qualtrics Survey Embeds Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Qualtrics Survey Embeds Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
28
15 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

35% escaped43 total outputs
Attack Surface

Qualtrics Survey Embeds Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_initinc\options.php:57
actionadmin_noticesinc\options.php:58
actionadmin_enqueue_scriptsinc\options.php:59
filterqse_register_settingsinc\settings\default.php:13
actionadmin_menuqualtrics-embed.php:20
Maintenance & Trust

Qualtrics Survey Embeds Maintenance & Trust

Maintenance Signals

WordPress version tested4.3.34
Last updatedAug 10, 2015
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

Qualtrics Survey Embeds Developer Profile

michaelryanmcneill

2 plugins · 3K total installs

74
trust score
Avg Security Score
93/100
Avg Patch Time
2883 days
View full developer profile
Detection Fingerprints

How We Detect Qualtrics Survey Embeds

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/qualtrics-survey-embeds/inc/js/tablefix.js
Version Parameters
qualtrics-survey-embeds/inc/js/tablefix.js?ver=

HTML / DOM Fingerprints

CSS Classes
wrapicon32
Data Attributes
placeholder
FAQ

Frequently Asked Questions about Qualtrics Survey Embeds