Simple Vote Me Security & Risk Analysis

wordpress.org/plugins/simple-vote-me

Integrate a simple voting plugin with smileys in your Wordpress!

10 active installs v1.3.1 PHP + WP 3.0+ Updated Sep 16, 2016
count-votegoodpollsmileysvote
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Simple Vote Me Safe to Use in 2026?

Generally Safe

Score 85/100

Simple Vote Me has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "simple-vote-me" plugin v1.3.1 presents a mixed security posture. On the positive side, it avoids dangerous functions, uses prepared statements for all SQL queries, has no file operations, and makes no external HTTP requests. Its vulnerability history is clean, indicating a potential for stable and secure development.

However, significant concerns arise from the static analysis. A considerable attack surface is exposed with two AJAX handlers lacking authentication checks. Furthermore, a striking 0% of output is properly escaped, which is a major weakness that can lead to various cross-site scripting (XSS) vulnerabilities. The taint analysis also reveals two flows with unsanitized paths, which, although not flagged as critical or high, still represent potential security weaknesses that require attention.

Despite the absence of known CVEs and a clean vulnerability history, the critical findings in the static analysis, particularly the unauthenticated AJAX endpoints and widespread unescaped output, necessitate caution. The plugin's strengths in SQL handling and lack of external dependencies are commendable, but these are overshadowed by vulnerabilities that could be exploited to compromise user data or site integrity. Therefore, while not overtly malicious, the plugin requires immediate attention to its input validation and output sanitization practices.

Key Concerns

  • Unprotected AJAX handlers
  • No output escaping
  • Unsanitized taint flows (2)
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Simple Vote Me Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Simple Vote Me Release Timeline

v1.3.1Current
v1.3
v1.2
v1.1.1
v1.1
v1.0.1
v1.0
Code Analysis
Analyzed Mar 16, 2026

Simple Vote Me Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
87
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped87 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
gt_simplevoteme_page_admin (admin.php:33)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Simple Vote Me Attack Surface

Entry Points3
Unprotected2

AJAX Handlers 2

noprivwp_ajax_simplevoteme_addvotesimple-vote-me.php:355
authwp_ajax_simplevoteme_addvotesimple-vote-me.php:356

Shortcodes 1

[simplevoteme] widget.php:22
WordPress Hooks 9
actionadmin_initadmin.php:3
actionadmin_menuadmin.php:4
actionadmin_initadmin.php:8
actionadd_meta_boxesadmin.php:481
actionplugins_loadedsimple-vote-me.php:39
actionwp_enqueue_scriptssimple-vote-me.php:98
filterthe_contentsimple-vote-me.php:311
actionwidgets_initwidget.php:101
actionwidgets_initwidget.php:168
Maintenance & Trust

Simple Vote Me Maintenance & Trust

Maintenance Signals

WordPress version tested4.6.30
Last updatedSep 16, 2016
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings7
Active installs10
Developer Profile

Simple Vote Me Developer Profile

Gon

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Simple Vote Me

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/simple-vote-me/css/simplevoteme.css/wp-content/plugins/simple-vote-me/css/simplevotemeadmin.css/wp-content/plugins/simple-vote-me/js/simple-vote-me.js
Script Paths
/wp-content/plugins/simple-vote-me/js/simple-vote-me.js
Version Parameters
simple-vote-me/css/simplevoteme.css?ver=simple-vote-me/css/simplevotemeadmin.css?ver=simple-vote-me/js/simple-vote-me.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-simplevoteme-id
JS Globals
gtsimplevotemeajax
FAQ

Frequently Asked Questions about Simple Vote Me