Social Polls by Wedgies.com Security & Risk Analysis

wordpress.org/plugins/wedgies-shortcode

Wedgies are polls that you can embed in your WordPress site and templates.

60 active installs v1.4.7 PHP + WP 2.5+ Updated Jan 15, 2016
pollpollingpollssocial-pollsurvey
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Social Polls by Wedgies.com Safe to Use in 2026?

Generally Safe

Score 85/100

Social Polls by Wedgies.com has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The "wedgies-shortcode" plugin v1.4.7 exhibits a strong security posture based on the provided static analysis. The complete absence of direct entry points like AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the attack surface. Furthermore, the code demonstrates good security practices by not utilizing dangerous functions, performing all SQL queries using prepared statements, and properly escaping all outputs. The lack of file operations and external HTTP requests also reduces potential vulnerabilities.

The vulnerability history is also clean, with no recorded CVEs. This suggests a well-maintained and secure plugin. While the absence of nonce and capability checks is noted, it is less concerning given the minimal attack surface and lack of directly exploitable entry points. The absence of taint analysis flows indicates that the plugin's code likely does not handle user-supplied data in a way that leads to known vulnerabilities through such paths.

In conclusion, this plugin appears to be very secure. Its limited attack surface and adherence to secure coding practices for database queries and output handling are significant strengths. The primary area for minor improvement would be to implement nonce and capability checks if any future functionality introduces new entry points, even if currently unexploited.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Social Polls by Wedgies.com Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Social Polls by Wedgies.com Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped2 total outputs
Attack Surface

Social Polls by Wedgies.com Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionwp_enqueue_scriptswedgies-shortcode.php:58
Maintenance & Trust

Social Polls by Wedgies.com Maintenance & Trust

Maintenance Signals

WordPress version tested4.4.34
Last updatedJan 15, 2016
PHP min version
Downloads15K

Community Trust

Rating70/100
Number of ratings6
Active installs60
Developer Profile

Social Polls by Wedgies.com Developer Profile

packagejson

1 plugin · 60 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Social Polls by Wedgies.com

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wedgies-shortcode/widgets.js
Script Paths
https://www.wedgies.com/js/widgets.js
Version Parameters
https://www.wedgies.com/js/widgets.js?ver=1.2

HTML / DOM Fingerprints

CSS Classes
wedgie-widget
Data Attributes
wd-pendingwd-typewd-version
Shortcode Output
<div class="wedgie-widget" wd-pending wd-type="embed" wd-version="v1" id="
FAQ

Frequently Asked Questions about Social Polls by Wedgies.com