
Qualtrics Survey Embeds Security & Risk Analysis
wordpress.org/plugins/qualtrics-survey-embedsAdds a Qualtrics Embed Handler to WordPress allowing for quick survey embeds.
Is Qualtrics Survey Embeds Safe to Use in 2026?
Generally Safe
Score 85/100Qualtrics Survey Embeds has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "qualtrics-survey-embeds" plugin v1.0 exhibits a generally good security posture based on the provided static analysis. It has no recorded CVEs, a clean vulnerability history, and the static analysis reveals no critical or high-severity issues in taint flows. Furthermore, it has zero identified AJAX handlers, REST API routes, shortcodes, or cron events, indicating a very small attack surface with no immediately apparent entry points. All identified SQL queries utilize prepared statements, and there are no file operations or external HTTP requests, which are positive indicators.
However, a significant concern arises from the output escaping. With 43 total outputs and only 35% properly escaped, there's a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. This lack of consistent output sanitization means that user-supplied data, if not handled carefully before being displayed, could be maliciously injected and executed in the user's browser. The absence of nonce and capability checks, while potentially mitigated by the lack of entry points, still represents a missed opportunity for robust security, especially if functionality were to be added or discovered later.
In conclusion, while the plugin's minimal attack surface and lack of historical vulnerabilities are strengths, the poor output escaping presents a clear and present danger. The vulnerability history shows no past issues, which is a positive sign, but the current code analysis highlights a critical weakness that needs immediate attention to prevent potential security breaches.
Key Concerns
- Low output escaping percentage
- Missing nonce checks
- Missing capability checks
Qualtrics Survey Embeds Security Vulnerabilities
Qualtrics Survey Embeds Code Analysis
Output Escaping
Qualtrics Survey Embeds Attack Surface
WordPress Hooks 5
Maintenance & Trust
Qualtrics Survey Embeds Maintenance & Trust
Maintenance Signals
Community Trust
Qualtrics Survey Embeds Alternatives
Embed PDF Viewer
embed-pdf-viewer
Embed a PDF from the Media Library or elsewhere via oEmbed or as a block into an iframe tag.
Disable Embeds
disable-embeds
Don’t like the enhanced embeds in WordPress 4.4? Easily disable the feature using this plugin.
Embed Privacy
embed-privacy
Embed Privacy prevents the loading of embedded external content and allows your site visitors to opt-in.
oEmbed Plus
oembed-plus
Adds support for embedding Facebook and Instagram posts in Block Editor (Gutenberg) and Classic Editor.
Embedly
embedly
The Embedly Plugin extends WordPress's auto-embed feature to give your blog more media types and style options.
Qualtrics Survey Embeds Developer Profile
2 plugins · 3K total installs
How We Detect Qualtrics Survey Embeds
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/qualtrics-survey-embeds/inc/js/tablefix.jsqualtrics-survey-embeds/inc/js/tablefix.js?ver=HTML / DOM Fingerprints
wrapicon32placeholder