Saber Feedback Button Security & Risk Analysis

wordpress.org/plugins/saber-feedback-button

Gather feedback, identify bugs and collect ideas from your visitors with our simple feedback button. 10-day free trial!

0 active installs v2.0.4 PHP + WP 4.6+ Updated Unknown
feedback-buttonfeedback-formfeedback-toolfeedback-widgetsaber-feedback
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Saber Feedback Button Safe to Use in 2026?

Generally Safe

Score 100/100

Saber Feedback Button has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The static analysis of saber-feedback-button v2.0.4 reveals a plugin with a seemingly small attack surface, as indicated by zero AJAX handlers, REST API routes, shortcodes, and cron events. The absence of dangerous functions and file operations is also a positive sign. Furthermore, all SQL queries appear to be using prepared statements, which is a good security practice. The plugin also has no recorded vulnerability history, suggesting it has been free of known exploits. However, the analysis highlights a critical weakness: 100% of the five identified output instances are not properly escaped. This lack of output escaping is a significant security concern, as it can lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is reflected directly in the output without sanitization. The absence of nonce and capability checks on any potential entry points, though the entry points are listed as zero, also raises a flag. While the plugin's current vulnerability history is clean, the lack of output escaping presents an immediate and exploitable risk that needs to be addressed.

Key Concerns

  • Output escaping is not performed
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

Saber Feedback Button Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Saber Feedback Button Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped5 total outputs
Attack Surface

Saber Feedback Button Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_menusaber-feedback-button.php:46
actionadmin_initsaber-feedback-button.php:49
actionwp_headsaber-feedback-button.php:52
actionadmin_initsaber-feedback-button.php:56
Maintenance & Trust

Saber Feedback Button Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedUnknown
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Saber Feedback Button Developer Profile

Steve McLeod

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Saber Feedback Button

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
https://widget.saberfeedback.com/v2/widget.js

HTML / DOM Fingerprints

HTML Comments
<!-- Saber Feedback button --><!-- End of Saber Feedback button -->
Data Attributes
id="legacy_options_warning" class="error notice"
JS Globals
window.Saber
FAQ

Frequently Asked Questions about Saber Feedback Button