UseResponse Feedback Widget Security & Risk Analysis

wordpress.org/plugins/useresponse-feedback-widget

Collect feedback within your WordPress website with an easy-to-use and customizable widget from UseResponse.

0 active installs v1.0 PHP 5.2.4+ WP 4.9+ Updated May 15, 2019
customer-feedbackfeedback-widgetfeedback-widget-for-websiteuser-feedbackwebsite-feedback
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is UseResponse Feedback Widget Safe to Use in 2026?

Generally Safe

Score 85/100

UseResponse Feedback Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

Based on the static analysis, the "useresponse-feedback-widget" v1.0 plugin exhibits a seemingly strong security posture with no identified dangerous functions, SQL injection vulnerabilities, or file operations. The lack of external HTTP requests and the absence of any recorded vulnerabilities in its history are also positive indicators. However, a significant concern arises from the complete absence of output escaping for all identified outputs. This means that any data displayed by the plugin could potentially be exploited to inject malicious code, leading to cross-site scripting (XSS) attacks. Furthermore, the lack of nonce checks and capability checks on all entry points, though zero in number, suggests a potential oversight in securing any future additions or if the current analysis missed any subtle entry points. While the plugin appears clean on the surface with no active exploits or known vulnerabilities, the unescaped output represents a tangible risk that needs immediate attention. The absence of any reported vulnerabilities in its history is good, but it doesn't guarantee future safety, especially given the identified output escaping issue.

Key Concerns

  • Output escaping is missing for all identified outputs
  • No nonce checks found
  • No capability checks found
Vulnerabilities
None known

UseResponse Feedback Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

UseResponse Feedback Widget Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

UseResponse Feedback Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped4 total outputs
Attack Surface

UseResponse Feedback Widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_menuuseresponse-feedback-widget.php:10
actionadmin_inituseresponse-feedback-widget.php:68
actionwp_footeruseresponse-feedback-widget.php:83
Maintenance & Trust

UseResponse Feedback Widget Maintenance & Trust

Maintenance Signals

WordPress version tested5.1.22
Last updatedMay 15, 2019
PHP min version5.2.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

UseResponse Feedback Widget Developer Profile

useresponse

2 plugins · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect UseResponse Feedback Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
//help.useresponse.com/public/sdk/chat-uriid_da39a3ee5e6b4b0d3255bfef95601890afd80709-38.js

HTML / DOM Fingerprints

CSS Classes
wrap
Data Attributes
id="UR_initiator"
JS Globals
document._fpu_
FAQ

Frequently Asked Questions about UseResponse Feedback Widget