
StatsFC Poll Security & Risk Analysis
wordpress.org/plugins/statsfc-pollThis widget will place a custom poll on your website.
Is StatsFC Poll Safe to Use in 2026?
Generally Safe
Score 85/100StatsFC Poll has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "statsfc-poll" v2.0.1 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, performing all SQL queries using prepared statements, and having no known historical vulnerabilities or currently unpatched CVEs. It also has a very small attack surface with only one entry point (a shortcode) and no external HTTP requests or file operations, which are all positive indicators. However, there are notable areas of concern. The plugin lacks any nonce checks or capability checks, meaning that even though the entry point is limited, there's no validation to ensure the requests are legitimate or authorized. Furthermore, half of the output operations are not properly escaped, creating a risk of Cross-Site Scripting (XSS) vulnerabilities. The taint analysis revealed flows with unsanitized paths, which, while not categorized as critical or high, still represent potential avenues for injection attacks if they are reachable by user-controlled input.
Key Concerns
- 0 Nonce checks
- 0 Capability checks
- 50% Output escaping
- 2 Flows with unsanitized paths
StatsFC Poll Security Vulnerabilities
StatsFC Poll Code Analysis
Output Escaping
Data Flow Analysis
StatsFC Poll Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
StatsFC Poll Maintenance & Trust
Maintenance Signals
Community Trust
StatsFC Poll Alternatives
Refiner Microsurveys Plugin
refiner
Install Refiner on your WordPress site and launch microsurveys within your website or web applicaiton.
Crowdsignal Forms
crowdsignal-forms
The Crowdsignal Forms plugin allows you to create and manage polls right from within the block editor.
Crowdsignal Dashboard – Polls, Surveys & more
polldaddy
Manage your Crowdsignal polls, surveys, quizzes, and ratings directly from the WordPress dashboard.
Democracy Poll
democracy-poll
WordPress polls plugin with multiple-choice, custom answers, cache compatibility, widgets, and shortcodes.
Quiz, Poll & Survey Maker by Opinion Stage
social-polls-by-opinionstage
Boost engagement and capture leads with interactive quizzes, polls, and surveys. Built for marketers, publishers, and businesses
StatsFC Poll Developer Profile
13 plugins · 360 total installs
How We Detect StatsFC Poll
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/statsfc-poll/poll.css/wp-content/plugins/statsfc-poll/poll.js/wp-content/plugins/statsfc-poll/poll.jsstatsfc-poll/poll.css?ver=statsfc-poll/poll.js?ver=HTML / DOM Fingerprints
id="statsfc-poll-name="statsfc-poll-statsfc-poll-StatsFC_Pollstatsfc_poll_<div id="statsfc-poll-statsfc-poll-