
UserFeedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds Security & Risk Analysis
wordpress.org/plugins/userfeedback-liteUltimate user feedback plugin to ask questions, surveys, polls, from your website in seconds
Is UserFeedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds Safe to Use in 2026?
Generally Safe
Score 88/100UserFeedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds has a strong security track record. Known vulnerabilities have been patched promptly.
The userfeedback-lite plugin version 1.11.1 exhibits a mixed security posture. While it demonstrates good practices such as a high percentage of prepared statements for SQL queries and properly escaped output, the presence of unprotected entry points in both AJAX handlers and REST API routes is a significant concern. The static analysis reveals 5 unprotected entry points out of a total of 48, which could be exploited by unauthenticated users. The vulnerability history, with 7 known CVEs including high-severity SQL Injection, Cross-site Scripting, and Missing Authorization, further raises red flags. Although there are currently no unpatched CVEs, the recurring nature of these critical vulnerability types suggests a historical pattern of insecure coding practices that require careful attention. Despite the positive aspects of code sanitization and prepared statements, the unprotected entry points and the past vulnerability record necessitate caution.
Key Concerns
- Unprotected AJAX handlers
- Unprotected REST API routes
- High number of known CVEs
- Previous high-severity SQL Injection vulnerabilities
- Previous high-severity XSS vulnerabilities
- Previous high-severity Missing Authorization vulnerabilities
UserFeedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds Security Vulnerabilities
CVEs by Year
Severity Breakdown
7 total CVEs
User Feedback <= 1.10.0 - Authenticated (Editor+) SQL Injection
User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds <= 1.8.0 - Missing Authorization to Information Disclosure
UserFeedback Lite <= 1.0.15 - Unauthenticated Stored Cross-Site Scripting via Name Parameter
User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds <= 1.0.13 - Unauthenticated Stored Cross-Site Scripting
User Feedback <= 1.0.10 - Missing Authorization
User Feedback <= 1.0.9 - Unauthenticated Cross-Site Scripting
User Feedback <= 1.0.7 - Unauthenticated Stored Cross-Site Scripting
UserFeedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
UserFeedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds Attack Surface
AJAX Handlers 20
REST API Routes 28
WordPress Hooks 85
Scheduled Events 3
Maintenance & Trust
UserFeedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds Maintenance & Trust
Maintenance Signals
Community Trust
UserFeedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds Alternatives
FeedFocal
feedfocal
Collect user feedback with our easy to use survey tools! Create surveys in seconds.
Mopinion Feedback Form
mopinion-feedback-form
Easy add feedback buttons and feedback forms to your website with the Mopinion.com Wordpress Plugin. Easy install, fast user insights.
Exit Intent Visitors Feedback – Trigger Feedback Popup on Exit Intent
visitors-feedback
Capture valuable feedback from your website visitors before they leave from your website.
Katorymnd Reaction Process Plugin
katorymnd-reaction-process
Elevate your WordPress site with dynamic feedback, ratings, and surveys for insightful user interaction.
SH Advance Polls
sh-advance-polls
You can create polls and surveys for your audience and observe the full analytics in the admin panel.
UserFeedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds Developer Profile
94 plugins · 23.5M total installs
How We Detect UserFeedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/userfeedback-lite/build/userfeedback-lite.min.css/wp-content/plugins/userfeedback-lite/build/userfeedback-lite.min.js/wp-content/plugins/userfeedback-lite/build/userfeedback-lite.min.jsuserfeedback-lite/build/userfeedback-lite.min.css?ver=userfeedback-lite/build/userfeedback-lite.min.js?ver=HTML / DOM Fingerprints
user-feedback-buttondata-userfeedback-lite-nonceUserFeedbackLiteConfig