
Simple Vote Me Security & Risk Analysis
wordpress.org/plugins/simple-vote-meIntegrate a simple voting plugin with smileys in your Wordpress!
Is Simple Vote Me Safe to Use in 2026?
Generally Safe
Score 85/100Simple Vote Me has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "simple-vote-me" plugin v1.3.1 presents a mixed security posture. On the positive side, it avoids dangerous functions, uses prepared statements for all SQL queries, has no file operations, and makes no external HTTP requests. Its vulnerability history is clean, indicating a potential for stable and secure development.
However, significant concerns arise from the static analysis. A considerable attack surface is exposed with two AJAX handlers lacking authentication checks. Furthermore, a striking 0% of output is properly escaped, which is a major weakness that can lead to various cross-site scripting (XSS) vulnerabilities. The taint analysis also reveals two flows with unsanitized paths, which, although not flagged as critical or high, still represent potential security weaknesses that require attention.
Despite the absence of known CVEs and a clean vulnerability history, the critical findings in the static analysis, particularly the unauthenticated AJAX endpoints and widespread unescaped output, necessitate caution. The plugin's strengths in SQL handling and lack of external dependencies are commendable, but these are overshadowed by vulnerabilities that could be exploited to compromise user data or site integrity. Therefore, while not overtly malicious, the plugin requires immediate attention to its input validation and output sanitization practices.
Key Concerns
- Unprotected AJAX handlers
- No output escaping
- Unsanitized taint flows (2)
- No nonce checks
- No capability checks
Simple Vote Me Security Vulnerabilities
Simple Vote Me Release Timeline
Simple Vote Me Code Analysis
Output Escaping
Data Flow Analysis
Simple Vote Me Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 9
Maintenance & Trust
Simple Vote Me Maintenance & Trust
Maintenance Signals
Community Trust
Simple Vote Me Alternatives
Crowdsignal Dashboard – Polls, Surveys & more
polldaddy
Manage your Crowdsignal polls, surveys, quizzes, and ratings directly from the WordPress dashboard.
WP-Polls
wp-polls
Adds an AJAX poll system to your WordPress blog. You can also easily add a poll into your WordPress's blog post/page.
Democracy Poll
democracy-poll
WordPress polls plugin with multiple-choice, custom answers, cache compatibility, widgets, and shortcodes.
Poll Maker – Versus Polls, Anonymous Polls, Image Polls
poll-maker
Poll Maker is a FREE WordPress poll plugin that will let you create customizable and professional online polls and voting for your WordPress website.
TotalPoll for Polls and Contests
totalpoll-lite
TotalPoll is a responsive and customizable WordPress poll plugin that will help you create voting contest, competition, image poll, simple poll.
Simple Vote Me Developer Profile
1 plugin · 10 total installs
How We Detect Simple Vote Me
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/simple-vote-me/css/simplevoteme.css/wp-content/plugins/simple-vote-me/css/simplevotemeadmin.css/wp-content/plugins/simple-vote-me/js/simple-vote-me.js/wp-content/plugins/simple-vote-me/js/simple-vote-me.jssimple-vote-me/css/simplevoteme.css?ver=simple-vote-me/css/simplevotemeadmin.css?ver=simple-vote-me/js/simple-vote-me.js?ver=HTML / DOM Fingerprints
data-simplevoteme-idgtsimplevotemeajax