
Really Simple Feedback Security & Risk Analysis
wordpress.org/plugins/really-simple-feedbackA really simple way to get feedback from your users.
Is Really Simple Feedback Safe to Use in 2026?
Generally Safe
Score 85/100Really Simple Feedback has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'really-simple-feedback' v1.0.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL query handling by exclusively using prepared statements and has no recorded vulnerability history, suggesting a lack of past critical issues. The absence of dangerous functions, file operations, and external HTTP requests further contributes to a generally secure foundation.
However, there are significant concerns related to the attack surface. The plugin exposes one REST API route without permission callbacks, which could potentially be exploited by unauthenticated users to perform unintended actions. Additionally, a notable weakness lies in output escaping, with only 25% of outputs being properly escaped. This could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not adequately sanitized before being displayed to other users.
While the lack of historical vulnerabilities is a good sign, the presence of unprotected entry points and insufficient output escaping in the current version warrants caution. The plugin's strengths in SQL handling and lack of exploitable taint flows are commendable, but the identified weaknesses in the attack surface and output sanitization require immediate attention to mitigate potential risks.
Key Concerns
- REST API route without permission callback
- Insufficient output escaping (75% unescaped)
- No nonce checks on entry points
Really Simple Feedback Security Vulnerabilities
Really Simple Feedback Release Timeline
Really Simple Feedback Code Analysis
Output Escaping
Really Simple Feedback Attack Surface
REST API Routes 3
WordPress Hooks 9
Maintenance & Trust
Really Simple Feedback Maintenance & Trust
Maintenance Signals
Community Trust
Really Simple Feedback Alternatives
UserFeedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds
userfeedback-lite
Ultimate user feedback plugin to ask questions, surveys, polls, from your website in seconds
Shortcoder — Create Shortcodes for Anything
shortcoder
Create custom "Shortcodes" easily for HTML, JavaScript, CSS code snippets and use the shortcodes within posts, pages & widgets
Asset CleanUp: Page Speed Booster
wp-asset-clean-up
Make your website load FASTER by stopping specific styles (.CSS) & scripts (.JS) from loading. It works best with a page caching plugin / service.
Enable jQuery Migrate Helper
enable-jquery-migrate-helper
Get information about calls to deprecated jQuery features in plugins or themes.
kk Star Ratings – Rate Post & Collect User Feedbacks
kk-star-ratings
kk Star Ratings allows blog visitors to involve and interact more effectively with your website by rating posts.
Really Simple Feedback Developer Profile
5 plugins · 10K total installs
How We Detect Really Simple Feedback
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/really-simple-feedback/dist/really-simple-feedback.js/wp-content/plugins/really-simple-feedback/dist/really-simple-feedback.css/wp-content/plugins/really-simple-feedback/dist/really-simple-feedback-admin.js/wp-content/plugins/really-simple-feedback/dist/really-simple-feedback-admin.css/wp-content/plugins/really-simple-feedback/dist/really-simple-feedback.js/wp-content/plugins/really-simple-feedback/dist/really-simple-feedback-admin.jsreally-simple-feedback/dist/really-simple-feedback.js?ver=1.0.0really-simple-feedback/dist/really-simple-feedback.css?ver=1.0.0really-simple-feedback/dist/really-simple-feedback-admin.js?ver=1.0.0really-simple-feedback/dist/really-simple-feedback-admin.css?ver=1.0.0HTML / DOM Fingerprints
rsf-widget-feedback-formrsf-widget-feedback-inputrsf-widget-feedback-textarearsf-widget-feedback-buttondata-rsf-widget-activersf_localized/wp-json/really-simple-feedback/v1/feedback/wp-json/really-simple-feedback/v1/mark-as-read/wp-json/really-simple-feedback/v1/mark-as-unread