Surveys by Feedback Cat Security & Risk Analysis

wordpress.org/plugins/surveys-by-feedback-cat

Surveys by Feedback Cat Helps You Grow Your Business Or Blog By Making It Easy To Gather Feedback Using Onpage User Surveys.

50 active installs v1.2.2 PHP + WP 4.0+ Updated Jul 16, 2015
feedbackfeedback-formpollsurveysurvey-form
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Surveys by Feedback Cat Safe to Use in 2026?

Generally Safe

Score 85/100

Surveys by Feedback Cat has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The "surveys-by-feedback-cat" plugin, version 1.2.2, exhibits a generally strong security posture based on the provided static analysis. The absence of identified CVEs, combined with zero critical or high severity vulnerabilities in its history, suggests a well-maintained and relatively secure codebase. The plugin also demonstrates good practices by utilizing prepared statements for its single SQL query, indicating an awareness of SQL injection prevention.

However, a significant concern arises from the complete lack of output escaping on all identified output points. This means that any data displayed to users, if not already properly sanitized before reaching these output points, could potentially be vulnerable to Cross-Site Scripting (XSS) attacks. The presence of file operations and a nonce check also indicate areas that could be leveraged if other vulnerabilities were present or introduced.

While the plugin's attack surface appears minimal with no registered AJAX handlers, REST API routes, or shortcodes, and its vulnerability history is clean, the unescaped output is a critical oversight that needs immediate attention. The plugin's strengths lie in its lack of known exploitable vulnerabilities and its secure database interaction. Its primary weakness is the lack of output sanitization, which poses a tangible risk of XSS.

Key Concerns

  • 0% output escaping
Vulnerabilities
None known

Surveys by Feedback Cat Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Surveys by Feedback Cat Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

Surveys by Feedback Cat Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
4
0 escaped
Nonce Checks
1
Capability Checks
0
File Operations
2
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

0% escaped4 total outputs
Attack Surface

Surveys by Feedback Cat Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
filterenter_title_hereincludes\FCA\FBC\Poll\Admin\Component.php:44
actionadmin_menuincludes\FCA\FBC\Poll\Admin\Component.php:103
actioninitincludes\FCA\FBC\Poll\Component.php:24
actionadmin_headincludes\FCA\FBC\Poll\Component.php:27
actionadmin_footerincludes\FCA\FBC\Poll\Component.php:28
actionwp_headincludes\FCA\FBC\Poll\Component.php:30
actionwp_enqueue_scriptsincludes\FCA\Loader.php:125
actionsave_postincludes\FCA\PostManager.php:32
filterwp_insert_post_dataincludes\FCA\PostManager.php:33
Maintenance & Trust

Surveys by Feedback Cat Maintenance & Trust

Maintenance Signals

WordPress version tested4.2.39
Last updatedJul 16, 2015
PHP min version
Downloads11K

Community Trust

Rating82/100
Number of ratings11
Active installs50
Developer Profile

Surveys by Feedback Cat Developer Profile

fatcatapps

13 plugins · 66K total installs

74
trust score
Avg Security Score
93/100
Avg Patch Time
250 days
View full developer profile
Detection Fingerprints

How We Detect Surveys by Feedback Cat

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/surveys-by-feedback-cat/includes/FCA/FBC/Poll/Admin/Component.js/wp-content/plugins/surveys-by-feedback-cat/includes/FCA/FBC/Poll/FrontEnd/Component.js/wp-content/plugins/surveys-by-feedback-cat/assets/css/frontend.css/wp-content/plugins/surveys-by-feedback-cat/assets/js/frontend.js/wp-content/plugins/surveys-by-feedback-cat/assets/js/admin.js
Script Paths
/wp-content/plugins/surveys-by-feedback-cat/assets/js/frontend.js/wp-content/plugins/surveys-by-feedback-cat/assets/js/admin.js
Version Parameters
surveys-by-feedback-cat/assets/css/frontend.css?ver=surveys-by-feedback-cat/assets/js/frontend.js?ver=surveys-by-feedback-cat/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
fca_feedback_cat_poll
Data Attributes
data-poll-id
JS Globals
fca_fbc
Shortcode Output
[feedback_cat_poll id='
FAQ

Frequently Asked Questions about Surveys by Feedback Cat