Feedback Company Security & Risk Analysis

wordpress.org/plugins/the-feedback-company

This plugin integrates Feedback Company review widgets and order registration into Wordpress/WooCommerce

800 active installs v3.3.2 PHP + WP 6.0+ Updated Feb 20, 2026
customersreviewreviewsshoppingwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Feedback Company Safe to Use in 2026?

Generally Safe

Score 100/100

Feedback Company has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The 'the-feedback-company' v3.3.2 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of any identified dangerous functions, file operations, or external HTTP requests is commendable. Furthermore, the plugin demonstrates awareness of security principles by utilizing prepared statements for a portion of its SQL queries and implementing proper output escaping on all identified outputs, albeit at a moderate rate (30%). The plugin also has a clean vulnerability history with no known CVEs, suggesting a good track record of security maintenance.

However, there are areas for concern that prevent a perfect score. The complete lack of nonce checks and capability checks across all entry points is a significant weakness. While the current static analysis shows no unprotected AJAX handlers or REST API routes, the absence of these fundamental security mechanisms means that any future additions or modifications to these components could inadvertently introduce vulnerabilities. This reliance on the absence of exploitable code rather than explicit security controls is a potential risk, especially as plugins evolve.

In conclusion, the plugin is currently in a relatively secure state, with no immediate critical flaws detected. Its clean history and some good coding practices are positive indicators. Nevertheless, the omission of essential security checks like nonces and capability checks for its entry points represents a notable weakness that, if unaddressed, could lead to vulnerabilities in the future. Addressing these missing checks would significantly bolster the plugin's overall security.

Key Concerns

  • Missing nonce checks on entry points
  • Missing capability checks on entry points
  • SQL queries not using prepared statements (75%)
  • Output escaping only 30% properly
Vulnerabilities
None known

Feedback Company Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Feedback Company Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
1 prepared
Unescaped Output
21
9 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

25% prepared4 total queries

Output Escaping

30% escaped30 total outputs
Attack Surface

Feedback Company Attack Surface

Entry Points7
Unprotected0

Shortcodes 7

[feedbackcompany_badge] the-feedback-company.php:253
[feedbackcompany_bar] the-feedback-company.php:254
[feedback_company_merchant_reviews_widget] the-feedback-company.php:256
[feedbackcompany_summary] the-feedback-company.php:258
[feedbackcompany_score] the-feedback-company.php:259
[feedbackcompany_reviews] the-feedback-company.php:260
[feedbackcompany_testimonial] the-feedback-company.php:261
WordPress Hooks 23
filterplugin_action_links_the-feedback-company/the-feedback-company.phpadmin.php:45
actionadmin_menuadmin.php:48
actionadmin_enqueue_scriptsadmin.php:63
actionadmin_initadmin.php:66
actionshutdownadmin.php:92
actionadmin_initadmin.php:96
actionadmin_initadmin.php:100
actionadmin_initadmin.php:104
actionadmin_initadmin.php:108
actioninitadmin.php:734
actionadmin_noticesthe-feedback-company.php:153
actionwp_footerthe-feedback-company.php:264
actioninitthe-feedback-company.php:316
actionwidgets_initthe-feedback-company.php:317
actionwoocommerce_order_status_changedwoocommerce.php:25
filterwc_get_templatewoocommerce.php:33
filterwoocommerce_product_get_rating_htmlwoocommerce.php:36
filterwoocommerce_blocks_product_grid_item_htmlwoocommerce.php:39
filterwoocommerce_product_tabswoocommerce.php:44
actionwoocommerce_after_single_productwoocommerce.php:48
filterwoocommerce_structured_data_productwoocommerce.php:53
actionwoocommerce_initwoocommerce.php:262
actionbefore_woocommerce_initwoocommerce.php:269
Maintenance & Trust

Feedback Company Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 20, 2026
PHP min version
Downloads22K

Community Trust

Rating0/100
Number of ratings0
Active installs800
Developer Profile

Feedback Company Developer Profile

FeedbackCompany

1 plugin · 800 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Feedback Company

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/the-feedback-company/css/style.css/wp-content/plugins/the-feedback-company/css/components.css/wp-content/plugins/the-feedback-company/js/feedbackcompany-sdk.js/wp-content/plugins/the-feedback-company/js/feedbackcompany-sdk.min.js/wp-content/plugins/the-feedback-company/js/feedbackcompany-widget-bar.js/wp-content/plugins/the-feedback-company/js/feedbackcompany-widget-main.js/wp-content/plugins/the-feedback-company/js/feedbackcompany-widget-sticky.js/wp-content/plugins/the-feedback-company/js/feedbackcompany-widget-product-extended.js+2 more
Script Paths
/wp-content/plugins/the-feedback-company/js/feedbackcompany-sdk.js/wp-content/plugins/the-feedback-company/js/feedbackcompany-sdk.min.js/wp-content/plugins/the-feedback-company/js/feedbackcompany-widget-bar.js/wp-content/plugins/the-feedback-company/js/feedbackcompany-widget-main.js/wp-content/plugins/the-feedback-company/js/feedbackcompany-widget-sticky.js/wp-content/plugins/the-feedback-company/js/feedbackcompany-widget-product-extended.js+2 more
Version Parameters
/wp-content/plugins/the-feedback-company/css/style.css?ver=/wp-content/plugins/the-feedback-company/css/components.css?ver=/wp-content/plugins/the-feedback-company/js/feedbackcompany-sdk.js?ver=/wp-content/plugins/the-feedback-company/js/feedbackcompany-sdk.min.js?ver=/wp-content/plugins/the-feedback-company/js/feedbackcompany-widget-bar.js?ver=/wp-content/plugins/the-feedback-company/js/feedbackcompany-widget-main.js?ver=/wp-content/plugins/the-feedback-company/js/feedbackcompany-widget-sticky.js?ver=/wp-content/plugins/the-feedback-company/js/feedbackcompany-widget-product-extended.js?ver=/wp-content/plugins/the-feedback-company/js/feedbackcompany-widget-product-reviews.js?ver=/wp-content/plugins/the-feedback-company/js/feedbackcompany-widget-product-summary.js?ver=

HTML / DOM Fingerprints

CSS Classes
feedbackcompany-widget-bar-containerfeedbackcompany-widget-main-containerfeedbackcompany-widget-sticky-containerfeedbackcompany-widget-product-extended-containerfeedbackcompany-widget-product-reviews-containerfeedbackcompany-widget-product-summary-container
Data Attributes
data-feedbackcompany-widget-uuiddata-feedbackcompany-widget-id
JS Globals
feedbackcompanyfeedbackcompanySDK
Shortcode Output
[feedbackcompany_badge][feedbackcompany_bar][feedback_company_merchant_reviews_widget][feedbackcompany_summary]
FAQ

Frequently Asked Questions about Feedback Company