
Starbox Voting Security & Risk Analysis
wordpress.org/plugins/starbox-votingThis plugin adds voting functionality for posts. visitors can vote for the post and against.
Is Starbox Voting Safe to Use in 2026?
Use With Caution
Score 64/100Starbox Voting has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The starbox-voting v2.0.4 plugin exhibits several concerning security weaknesses despite a seemingly low attack surface and no external dependencies. The static analysis reveals a significant lack of proper output escaping, with 100% of identified outputs not being properly escaped. This is a critical vulnerability that could lead to Cross-Site Scripting (XSS) attacks, allowing attackers to inject malicious scripts into the site. Furthermore, the use of the `create_function` is a deprecated and potentially insecure practice. The taint analysis also highlights an issue with unsanitized paths, indicating a potential for insecure file operations or data manipulation, even though no explicit file operations were detected. The plugin's history of a medium-severity 'Exposure of Sensitive Information' CVE, which remains unpatched, adds to the overall risk profile. While the absence of AJAX handlers, REST API routes, shortcodes, and cron events limits direct attack vectors, the identified code quality issues and historical vulnerability suggest a developer who may not prioritize robust security practices. The combination of unescaped output, potential unsanitized data flow, and a past unpatched vulnerability presents a notable risk to any WordPress site using this plugin.
Key Concerns
- 0% properly escaped output
- Use of dangerous function 'create_function'
- Taint flow with unsanitized paths
- Unpatched medium severity CVE
- 20% SQL queries using prepared statements
- No nonce checks
- No capability checks
Starbox Voting Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Starbox Voting <= 2.0.4 - Full Path Disclosure
Starbox Voting Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Starbox Voting Attack Surface
WordPress Hooks 3
Maintenance & Trust
Starbox Voting Maintenance & Trust
Maintenance Signals
Community Trust
Starbox Voting Alternatives
Vote It Up
vote-it-up
The Vote It Up plugin enables visitors to vote for and against posts.
WP Popular Posts
wordpress-popular-posts
A highly customizable, easy-to-use popular posts plugin!
kk Star Ratings – Rate Post & Collect User Feedbacks
kk-star-ratings
kk Star Ratings allows blog visitors to involve and interact more effectively with your website by rating posts.
WP-Ranking PRO
wp-ranking-pro
"WP-Ranking PRO" totals a page view, and into which a popular article can be formed by various elements or periods.
Gp post Like
gp-post-like
Allow user add post like button above or below post content.
Starbox Voting Developer Profile
2 plugins · 20 total installs
How We Detect Starbox Voting
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/starbox-voting/css/starbox.css/wp-content/plugins/starbox-voting/css/option_style.css/wp-content/plugins/starbox-voting/js/prototype.js/wp-content/plugins/starbox-voting/js/scriptaculous.js/wp-content/plugins/starbox-voting/js/starbox.js/wp-content/plugins/starbox-voting/js/function.js.php/wp-content/plugins/starbox-voting/js/starbox.js/wp-content/plugins/starbox-voting/js/function.js.phpstarbox.css?ver=prototype.js?ver=scriptaculous.js?ver=starbox.js?ver=function.js.php?ver=HTML / DOM Fingerprints
starboxYou can see more information at : http://www.sealedbox.cn/starbox/**** Change Log ****starbox_buttonstarbox_overlaystarbox_classstarbox_ghoststarbox_version