
Survicate Security & Risk Analysis
wordpress.org/plugins/survicateWith Survicate, you can collect feedback using contextual surveys that feel like a part of your website.
Is Survicate Safe to Use in 2026?
Generally Safe
Score 85/100Survicate has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The Survicate plugin version 4.1.3 exhibits a generally strong security posture based on the static analysis provided. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points is a significant strength, indicating a minimal attack surface. Furthermore, the code signals show no dangerous functions, all SQL queries utilize prepared statements, and there are no file operations or bundled libraries, all of which are positive security indicators. The presence of external HTTP requests and a relatively high percentage of unescaped output (20%) are minor points of concern.
The taint analysis, while limited in scope with only two flows analyzed, did identify two flows with unsanitized paths. Although these did not reach critical or high severity, this finding warrants attention as it suggests potential pathways for data manipulation if exploited. The plugin's vulnerability history is exceptionally clean, with no recorded CVEs, which suggests a mature and well-maintained codebase or a history of responsible security practices. However, the lack of reported vulnerabilities should not lead to complacency, especially given the identified taint flows.
In conclusion, Survicate v4.1.3 appears to be a secure plugin with a well-defined and protected attack surface. The absence of known vulnerabilities and good practices like prepared statements are commendable. The primary areas for improvement and potential risk lie in the two identified taint flows with unsanitized paths and the 20% of output that is not properly escaped, which could become issues if exposed to untrusted input. Overall, the plugin demonstrates a good security foundation.
Key Concerns
- Flows with unsanitized paths found
- Unescaped output detected (20%)
Survicate Security Vulnerabilities
Survicate Release Timeline
Survicate Code Analysis
Output Escaping
Data Flow Analysis
Survicate Attack Surface
WordPress Hooks 5
Maintenance & Trust
Survicate Maintenance & Trust
Maintenance Signals
Community Trust
Survicate Alternatives
Refiner Microsurveys Plugin
refiner
Install Refiner on your WordPress site and launch microsurveys within your website or web applicaiton.
UserFeedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds
userfeedback-lite
Ultimate user feedback plugin to ask questions, surveys, polls, from your website in seconds
Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder
everest-forms
The best WordPress form builder. Create contact forms, payment forms, conversational forms, custom forms, surveys, & quizzes using drag and drop.
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder
form-maker
Form Maker is a user-friendly contact form builder that allows to create forms for any purpose, from a simple contact form to multi page survey forms
Contact Form & SMTP Plugin for WordPress by PirateForms
pirate-forms
A simple and effective WordPress contact form & SMTP plugin. Compatible with best themes out there, is both a secure and responsive contact form p …
Survicate Developer Profile
1 plugin · 200 total installs
How We Detect Survicate
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/survicate/css/style.css//survey.survicate.com/workspaces/HTML / DOM Fingerprints
survicate-paddingsurvicate-form-areaid="survicate-tracking-code"window.survicate