RIACO Feedback Security & Risk Analysis

wordpress.org/plugins/riaco-feedback

RIACO Feedback allows users to submit feature requests or feedback, vote on existing suggestions, and manage them via the WordPress admin.

0 active installs v1.0.0 PHP 8.0+ WP 6.2+ Updated Dec 28, 2025
feature-requestsfeedbackvotes
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is RIACO Feedback Safe to Use in 2026?

Generally Safe

Score 100/100

RIACO Feedback has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The riaco-feedback plugin v1.0.0 exhibits a strong security posture based on the provided static analysis and vulnerability history. A significant strength is the complete absence of critical or high-severity taint flows, along with 100% of SQL queries utilizing prepared statements, which mitigates common injection risks. Furthermore, the plugin demonstrates good practices by implementing nonce checks on all identified AJAX handlers and has a history free of known vulnerabilities.

However, a minor concern arises from the output escaping. While 80% of outputs are properly escaped, the remaining 20% could potentially be vulnerable to cross-site scripting (XSS) if the unescaped data originates from user input or untrusted sources. This is a moderate risk, as the absence of known vulnerabilities and the presence of other security measures like nonce checks and prepared statements reduce the overall impact. The plugin's small attack surface and lack of bundled libraries are also positive indicators.

In conclusion, riaco-feedback v1.0.0 appears to be a relatively secure plugin. The developers have implemented essential security features effectively. The primary area for improvement would be to ensure all output is consistently escaped to eliminate any potential XSS vectors. The lack of historical vulnerabilities is a very positive sign, suggesting a commitment to secure coding practices.

Key Concerns

  • Unescaped output detected
Vulnerabilities
None known

RIACO Feedback Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

RIACO Feedback Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
8 prepared
Unescaped Output
18
73 escaped
Nonce Checks
8
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared8 total queries

Output Escaping

80% escaped91 total outputs
Data Flows
All sanitized

Data Flow Analysis

5 flows
handle_vote (includes\Ajax.php:34)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

RIACO Feedback Attack Surface

Entry Points11
Unprotected0

AJAX Handlers 8

authwp_ajax_riaco_voteincludes\Ajax.php:24
noprivwp_ajax_riaco_voteincludes\Ajax.php:25
authwp_ajax_riaco_unvoteincludes\Ajax.php:27
noprivwp_ajax_riaco_unvoteincludes\Ajax.php:28
authwp_ajax_riaco_paginateincludes\Ajax.php:30
noprivwp_ajax_riaco_paginateincludes\Ajax.php:31
authwp_ajax_riaco_submit_featureincludes\SubmitForm.php:13
noprivwp_ajax_riaco_submit_featureincludes\SubmitForm.php:14

Shortcodes 3

[riaco_feedback_features_board] includes\Shortcodes.php:28
[riaco_feedback_roadmap] includes\Shortcodes.php:29
[riaco_feedback_features] includes\SubmitForm.php:12
WordPress Hooks 29
filterpost_row_actionsincludes\Admin.php:12
actionadmin_initincludes\Admin.php:13
actionrestrict_manage_postsincludes\AdminFilters.php:12
filterparse_queryincludes\AdminFilters.php:13
actionwp_dashboard_setupincludes\DashboardWidget.php:12
actionadmin_initincludes\Permalink.php:12
actionplugins_loadedincludes\Plugin.php:46
actionadmin_enqueue_scriptsincludes\Plugin.php:94
actioninitincludes\PostType.php:12
actionwp_headincludes\PostType.php:13
filterposts_fieldsincludes\Query.php:10
filterposts_joinincludes\Query.php:11
filterposts_groupbyincludes\Query.php:12
filterposts_orderbyincludes\Query.php:13
actionadmin_menuincludes\Settings.php:12
actionadmin_initincludes\Settings.php:13
actionwp_enqueue_scriptsincludes\Shortcodes.php:41
actionwp_enqueue_scriptsincludes\Shortcodes.php:88
actionriaco_feedback_submittedincludes\SubmitForm.php:15
actioninitincludes\TaxonomyProject.php:14
actionadmin_menuincludes\TaxonomyProject.php:15
actionadd_meta_boxesincludes\TaxonomyProject.php:16
actionsave_post_riaco_feedbackincludes\TaxonomyProject.php:17
actionset_object_termsincludes\TaxonomyProject.php:20
actioninitincludes\TaxonomyStatus.php:16
actionadmin_menuincludes\TaxonomyStatus.php:17
actionadd_meta_boxesincludes\TaxonomyStatus.php:18
actionsave_post_riaco_feedbackincludes\TaxonomyStatus.php:19
actionset_object_termsincludes\TaxonomyStatus.php:22
Maintenance & Trust

RIACO Feedback Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 28, 2025
PHP min version8.0
Downloads90

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

RIACO Feedback Developer Profile

robertoiacono

12 plugins · 90 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect RIACO Feedback

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/riaco-feedback/assets/src/css/admin.css
Version Parameters
riaco-feedback/assets/src/css/admin.css?ver=

HTML / DOM Fingerprints

CSS Classes
riaco-feedback-features__listriaco-feedback-features__message-noneriaco-feedback-features__paginationriaco-feedback-roadmap
Data Attributes
data-num-pages
Shortcode Output
<div class="riaco-feedback-features__list flex flex-col gap-6 "><div id="riaco-feedback-features__pagination" class="mt-6" data-num-pages="<div class="riaco-feedback-roadmap grid grid-cols-1 md:grid-cols-3 gap-6">
FAQ

Frequently Asked Questions about RIACO Feedback