
Visual Feedback Security & Risk Analysis
wordpress.org/plugins/visual-feedbackVisual Feedback enables you to provide feedback on your WordPress site by simply clicking and commenting.
Is Visual Feedback Safe to Use in 2026?
Generally Safe
Score 85/100Visual Feedback has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "visual-feedback" plugin v1.3.1 demonstrates a generally strong security posture based on the provided static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events, particularly those without authentication checks, significantly limits the potential attack surface. The code also avoids dangerous functions and file operations, and all SQL queries are properly prepared, mitigating common database-related vulnerabilities. The fact that there are no recorded CVEs for this plugin further suggests a history of stable and secure development.
However, there are a couple of areas that warrant attention. While there is one capability check present, the lack of nonces on entry points (though the attack surface is currently zero) is a missed opportunity for robust security. Additionally, the output escaping is only 61% properly implemented, which could potentially lead to cross-site scripting (XSS) vulnerabilities if malicious data is ever introduced through a flow not yet identified. The taint analysis shows no critical or high-severity unsanitized paths, which is positive, but the limited number of flows analyzed (2) means this is not an exhaustive picture.
In conclusion, the "visual-feedback" plugin appears to be relatively secure, with a commendable lack of known vulnerabilities and good practices regarding SQL and dangerous functions. The main areas for improvement are enhancing output escaping and considering nonce implementation as the plugin evolves. The limited taint analysis scope should also be noted as a potential area where more in-depth analysis might be beneficial if the plugin's functionality grows.
Key Concerns
- Output escaping is only 61% proper
- No nonce checks on entry points
Visual Feedback Security Vulnerabilities
Visual Feedback Release Timeline
Visual Feedback Code Analysis
Output Escaping
Data Flow Analysis
Visual Feedback Attack Surface
WordPress Hooks 4
Maintenance & Trust
Visual Feedback Maintenance & Trust
Maintenance Signals
Community Trust
Visual Feedback Alternatives
Atarim – Visual Feedback, Review & AI Collaboration
atarim-visual-collaboration
Make collecting feedback on WordPress sites MUCH faster and easier, with the visual collaboration tool used on over 120,000 websites worldwide.
Simple Commenter – Website Feedback tool
simple-commenter
The website feedback tool your clients will actually use. Collect visual feedback directly on your site—no training required.
SureFeedback Cloud
surefeedback-cloud
SureFeedback Cloud helps teams collect visual feedback on WordPress sites and designs. Fast client sharing, zero hosting needed.
Supernifty Bublz
supernifty-bublz
Click anything on your site. Pin a task to it. Track it on a kanban board. Bug reporting and feedback built into WordPress.
Marker.io – Visual Website Feedback
marker-io
Collect visual website feedback from colleagues and clients on your WordPress site.
Visual Feedback Developer Profile
1 plugin · 10 total installs
How We Detect Visual Feedback
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/visual-feedback/admin/css/visual-feedback-plugin-settings.min.css/wp-content/plugins/visual-feedback/admin/js/visual-feedback-plugin-settings.min.js/wp-content/plugins/visual-feedback/public/css/s.min.css/wp-content/plugins/visual-feedback/public/js/c-3.0.4.min.js/wp-content/plugins/visual-feedback/public/js/v.min.jsadmin/js/visual-feedback-plugin-settings.min.jspublic/js/v.min.jspublic/js/c-3.0.4.min.jsHTML / DOM Fingerprints
vf-user-specified-event-idvisual_feedback_by_timeline__plugin_settings_formdata-vf-edit-linkwindow.teidvfwindow.tio_vf_eat