Feeback is the easiest way to gather feedback, identify bugs, and collect ideas from website visitors. Free Trial!

10 active installs v1.3.51 PHP + WP 3.6+ Updated Jan 2, 2021
feedbackpollssurveyuser-feedback
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Feedback Safe to Use in 2026?

Generally Safe

Score 85/100

Feedback has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The 'user-feedback-and-ratings-by-social-intents' plugin version 1.3.51 exhibits a concerning security posture primarily due to a complete lack of output escaping. While the static analysis indicates a limited attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are unprotected, and no known vulnerabilities in its history, the absence of proper output escaping for all 14 identified outputs is a significant risk. This means that any data displayed by the plugin, whether user-generated or otherwise, could be rendered without proper sanitization, opening the door for cross-site scripting (XSS) attacks. The plugin also has no recorded vulnerabilities, which is a positive sign, but this cannot overshadow the critical flaw in output handling. In conclusion, despite a seemingly clean record and a small attack surface, the critical deficiency in output escaping makes this plugin a high-risk component for any WordPress site.

Key Concerns

  • All outputs are unescaped
Vulnerabilities
None known

Feedback Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Feedback Release Timeline

v1.3.51Current
v1.3.50
v1.3.49
v1.3.48
v1.3.47
v1.3.9
v1.3.8
v1.3.7
v1.3.6
v1.3.5
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

Feedback Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
14
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped14 total outputs
Attack Surface

Feedback Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actioninituser-feedback-and-ratings-by-socialintents.php:12
actionadmin_noticesuser-feedback-and-ratings-by-socialintents.php:13
filterplugin_action_linksuser-feedback-and-ratings-by-socialintents.php:14
actionwp_footeruser-feedback-and-ratings-by-socialintents.php:15
actionadmin_footeruser-feedback-and-ratings-by-socialintents.php:16
actionadmin_menuuser-feedback-and-ratings-by-socialintents.php:24
actionadmin_menuuser-feedback-and-ratings-by-socialintents.php:25
Maintenance & Trust

Feedback Maintenance & Trust

Maintenance Signals

WordPress version tested5.6.17
Last updatedJan 2, 2021
PHP min version
Downloads43K

Community Trust

Rating70/100
Number of ratings4
Active installs10
Developer Profile

Feedback Developer Profile

socialintents

6 plugins · 550 total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Feedback

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/user-feedback-and-ratings-by-social-intents/socialintents.png
Script Paths
http://www.socialintents.com/api/fb/socialintents.1.3.js

HTML / DOM Fingerprints

CSS Classes
siuf_tab_textsiuf_noAccountSpan
HTML Comments
<!-- Feedback by www.socialintents.com -->
Data Attributes
id="siuf_widgetID"id="siuf_tab_text"id="siuf_submit"id="siuf_noAccountSpan"id="siuf_register"id="siuf_registerComplete"+4 more
JS Globals
socialintents
FAQ

Frequently Asked Questions about Feedback