
Simple Poll Security & Risk Analysis
wordpress.org/plugins/smp-simple-pollThe Simple Poll is a voting poll system into your post, pages and everywhere in website by just a shortcode. Add poll system to your post by placing s …
Is Simple Poll Safe to Use in 2026?
Generally Safe
Score 85/100Simple Poll has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The smp-simple-poll plugin v2.0.3 presents a mixed security posture. On the positive side, it demonstrates good practices by using prepared statements for all SQL queries and generally performs well on output escaping, with 82% of outputs properly escaped. There are no recorded vulnerabilities (CVEs), and the code does not appear to utilize dangerous functions or perform file operations, external HTTP requests, or bundle libraries. This suggests a developer who is mindful of common security pitfalls.
However, the plugin's attack surface is a notable concern. It exposes two AJAX handlers, and critically, both of these lack authentication checks. This means any unauthenticated user could potentially interact with these AJAX endpoints, leading to unintended actions or information disclosure. While the taint analysis shows no issues, the lack of authentication on these entry points is a significant risk. The presence of one shortcode also adds to the attack surface, although its security is not detailed in the provided data.
The absence of known vulnerabilities and historical issues is a strong positive indicator. It suggests that the plugin has either not been a target or has been developed with sufficient security awareness to avoid common flaws. However, this should not lead to complacency, especially given the identified unprotected AJAX endpoints. The plugin's strengths lie in its careful database interaction and output handling, but its weaknesses stem from its exposed, unauthenticated AJAX functionality.
Key Concerns
- Unprotected AJAX handlers
- Low output escaping percentage (18% unescaped)
Simple Poll Security Vulnerabilities
Simple Poll Code Analysis
SQL Query Safety
Output Escaping
Simple Poll Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 12
Maintenance & Trust
Simple Poll Maintenance & Trust
Maintenance Signals
Community Trust
Simple Poll Alternatives
YOP Poll
yop-poll
Use a full option polling solution to get the answers you need. YOP Poll is the perfect, easy to use poll plugin for your WordPress site.
WP-Polls
wp-polls
Adds an AJAX poll system to your WordPress blog. You can also easily add a poll into your WordPress's blog post/page.
Poll Maker – Versus Polls, Anonymous Polls, Image Polls
poll-maker
Poll Maker is a FREE WordPress poll plugin that will let you create customizable and professional online polls and voting for your WordPress website.
Better WordPress Polldaddy Polls
bwp-polldaddy
Helps you add Polldaddy Polls to your WordPress website easily.
CPM All in one Poll
cpm-all-in-one-responsive-poll
CPM All in One Poll is an awesome plugin that lets you create Polls with 7 different chart types, and is fully translatable.
Simple Poll Developer Profile
1 plugin · 10 total installs
How We Detect Simple Poll
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/smp-simple-poll/assets/css/smpp-poll-backend.css/wp-content/plugins/smp-simple-poll/assets/js/smpp-poll-backend.js/wp-content/plugins/smp-simple-poll/assets/css/smpp-poll-frontend.css/wp-content/plugins/smp-simple-poll/assets/js/smpp-ajax-poll.js/wp-content/plugins/smp-simple-poll/assets/js/smpp-poll-frontend.js/wp-content/plugins/smp-simple-poll/dist/blocks.style.build.css/wp-content/plugins/smp-simple-poll/dist/blocks.build.js/wp-content/plugins/smp-simple-poll/dist/blocks.editor.build.css/wp-content/plugins/smp-simple-poll/assets/js/smpp-poll-backend.js/wp-content/plugins/smp-simple-poll/assets/js/smpp-ajax-poll.js/wp-content/plugins/smp-simple-poll/assets/js/smpp-poll-frontend.js/wp-content/plugins/smp-simple-poll/dist/blocks.build.jssmp-poll-ajax?ver=smpp-poll-frontend?ver=smpp-poll-backend?ver=smpp-ajax-poll?ver=smpp-poll-backend.js?ver=smpp-ajax-poll.js?ver=smpp-poll-frontend.js?ver=blocks.style.build.css?ver=blocks.build.js?ver=blocks.editor.build.css?ver=HTML / DOM Fingerprints
smpp-poll-optionssmpp-poll-questionsmpp-poll-submitsmpp-poll-results-wrapperdata-poll-idsmpp_ajax_objwpRestApicgbGlobal/wp-json/smp-simple-poll/v1/get-poll[SIMPLE_POLL