
Userback Security & Risk Analysis
wordpress.org/plugins/userbackUserback is a powerful visual feedback tool that makes it easy to collect website feedback, report bugs, and collaborate with your team—all from your …
Is Userback Safe to Use in 2026?
Mostly Safe
Score 76/100Userback is generally safe to use. 2 past CVEs were resolved. Keep it updated.
The Userback plugin v1.0.17 exhibits a mixed security posture. On the positive side, the static analysis reveals a relatively small attack surface consisting of only two AJAX handlers, and importantly, none of these entry points appear to be unprotected by authentication checks. The presence of nonce and capability checks on these handlers further strengthens the access control mechanisms. The code also demonstrates good practices by utilizing prepared statements for the majority of its SQL queries and shows an effort towards output escaping, although not universally applied.
However, the vulnerability history presents a significant concern. With two known CVEs and one remaining unpatched, including two medium severity vulnerabilities, the plugin has a track record of security flaws. The common vulnerability types of Missing Authorization and Cross-Site Request Forgery (CSRF) are particularly worrying as they directly relate to how the plugin handles user actions and data. The fact that the last vulnerability was so recent (2025-12-12) suggests a continued pattern of issues that are not being fully addressed.
In conclusion, while the current static analysis shows some positive security indicators like protected entry points and good SQL practices, the historical vulnerability data overshadows these strengths. The presence of unpatched medium severity vulnerabilities, especially those related to authorization and CSRF, indicates a critical need for immediate attention. Users should be wary of the potential for exploitation given this history, and developers should prioritize fixing the existing CVEs and implementing more robust, universal sanitization and escaping.
Key Concerns
- Unpatched CVE: 2
- Medium severity CVEs: 2
- Output escaping: 56% properly escaped
- SQL queries: 33% not using prepared statements
Userback Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Userback <= 1.0.15 - Missing Authorization to Authenticated (Subscriber+) Plugin's Configuration Exposure
Userback <= 1.0.13 - Cross-Site Request Forgery
Userback Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Userback Attack Surface
AJAX Handlers 2
WordPress Hooks 3
Maintenance & Trust
Userback Maintenance & Trust
Maintenance Signals
Community Trust
Userback Alternatives
UserFeedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds
userfeedback-lite
Ultimate user feedback plugin to ask questions, surveys, polls, from your website in seconds
Marker.io – Visual Website Feedback
marker-io
Collect visual website feedback from colleagues and clients on your WordPress site.
FeedFocal
feedfocal
Collect user feedback with our easy to use survey tools! Create surveys in seconds.
Feedbucket – Website Feedback Tool
feedbucket
Enable your clients and team members to submit feedback using screenshot and recordings on your WordPress site.
Usersnap
usersnap
Usersnap: The feedback platform designed to capture, organize, and respond to user feedback seamlessly.
Userback Developer Profile
1 plugin · 2K total installs
How We Detect Userback
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/userback/assets/logo.pnghttps://static.userback.io/widget/v1.js/userback/javascript/admin.js?ver=/userback/css/admin.css?ver=HTML / DOM Fingerprints
<!-- Userback --><!-- END -->data-userback-access-tokenUserbackUserbackAjax/wp-json/wp/v2/pages