
Surmetric Surveys Security & Risk Analysis
wordpress.org/plugins/surmetric-surveysA WordPress plugin that allows you to post a survey/poll to your WordPress site.
Is Surmetric Surveys Safe to Use in 2026?
Generally Safe
Score 85/100Surmetric Surveys has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The surmetric-surveys plugin version 1.0 exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests are positive indicators. Notably, all SQL queries utilize prepared statements, which significantly mitigates SQL injection risks. The presence of a nonce check is also a good practice. However, a significant concern arises from the output escaping. With 19 total outputs and only 58% properly escaped, there's a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, as a considerable portion of output is not being sanitized before rendering.
The plugin's vulnerability history is clean, with no recorded CVEs. This suggests that, to date, the plugin has not been a target for widespread exploitation or has not had publicly disclosed vulnerabilities. While this is a positive sign, it's important to note that a clean history doesn't guarantee future security, especially when combined with identified code quality concerns like insufficient output escaping.
In conclusion, surmetric-surveys v1.0 demonstrates strong foundational security by avoiding common pitfalls like direct SQL queries and external requests. However, the substantial percentage of unescaped output presents a clear and present danger of XSS attacks. The lack of historical vulnerabilities is a strength, but the identified output sanitization issue requires immediate attention to improve the overall security posture and protect against potential client-side exploits.
Key Concerns
- Insufficient output escaping detected
Surmetric Surveys Security Vulnerabilities
Surmetric Surveys Release Timeline
Surmetric Surveys Code Analysis
Output Escaping
Data Flow Analysis
Surmetric Surveys Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
Surmetric Surveys Maintenance & Trust
Maintenance Signals
Community Trust
Surmetric Surveys Alternatives
RAWR for WordPress
rawr
You got information - we got conversation! Rawr widgets sit right within the story and help your users to express and share their opinion with others.
TotalSurvey for Survey, Quiz and Form
totalsurvey
Create satisfaction survey, engaging quiz, gather feedback and run exam with the best WordPress survey and quiz plugin.
Pinpoll
pinpoll
Engage with your audience.
Formera
formera
An advanced, high-performance Survey Maker with a premium SaaS-style interface.
Plugiva Pulse
plugiva-pulse
Create lightweight feedback forms and quick polls with yes/no, emoji, and text responses inside WordPress.
Surmetric Surveys Developer Profile
1 plugin · 0 total installs
How We Detect Surmetric Surveys
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/surmetric-surveys/load_iframe.js/wp-content/plugins/surmetric-surveys/settings_page.jssurmetric-surveys/load_iframe.js?ver=surmetric-surveys/settings_page.js?ver=HTML / DOM Fingerprints
sophware-surveydata-uiddata-style<div class='sophware-survey'