WiflyDemoFeedbackComposer Security & Risk Analysis

wordpress.org/plugins/wiflydemofeedbackcomposer

The plugin is responsible for collecting and displaying feedback

0 active installs v1.0.3 PHP 7.4+ WP 5.5+ Updated Mar 27, 2023
custom-fields-in-frontenddisplay-custom-fieldsfeedbackshortcodewidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WiflyDemoFeedbackComposer Safe to Use in 2026?

Generally Safe

Score 85/100

WiflyDemoFeedbackComposer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The static analysis of wiflydemofeedbackcomposer v1.0.3 indicates a generally good security posture. The plugin exhibits a strong adherence to secure coding practices, with a significant percentage of SQL queries utilizing prepared statements and a good proportion of output being properly escaped. The absence of any identified taint flows, dangerous functions, or external HTTP requests further contributes to its positive security profile. Furthermore, the plugin's attack surface appears to be minimal, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events without authentication checks. This suggests a well-contained design that limits potential entry points for malicious actors.

However, a notable concern is the complete lack of capability checks. While nonce checks are present, the absence of capability checks means that any user, regardless of their role or permissions, could potentially interact with the plugin's functionality. This could be a significant oversight, especially if the plugin handles sensitive data or performs actions that should be restricted to administrators or specific user roles. The vulnerability history is also a strong positive, showing no known CVEs, which suggests the plugin has not historically been a target or has been maintained effectively. In conclusion, wiflydemofeedbackcomposer v1.0.3 demonstrates many strengths in secure coding, but the critical omission of capability checks presents a significant weakness that requires immediate attention to ensure proper authorization is enforced.

Key Concerns

  • Missing capability checks
Vulnerabilities
None known

WiflyDemoFeedbackComposer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WiflyDemoFeedbackComposer Code Analysis

Dangerous Functions
0
Raw SQL Queries
6
16 prepared
Unescaped Output
6
15 escaped
Nonce Checks
5
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

SQL Query Safety

73% prepared22 total queries

Output Escaping

71% escaped21 total outputs
Attack Surface

WiflyDemoFeedbackComposer Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_menuadmin\class.wifly-demo.admin.php:7
actionwp_loadedadmin\class.wifly-demo.admin.php:8
actionadmin_post_get_dumpadmin\class.wifly-demo.admin.php:9
actionadmin_post_add_feedbackadmin\class.wifly-demo.admin.php:10
actionadmin_post_add_categoryadmin\class.wifly-demo.admin.php:11
actionadmin_post_edit_categoryadmin\class.wifly-demo.admin.php:12
actionadmin_post_delete_categoryadmin\class.wifly-demo.admin.php:13
actiontemplate_redirectadmin\class.wifly-demo.admin.php:19
Maintenance & Trust

WiflyDemoFeedbackComposer Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedMar 27, 2023
PHP min version7.4
Downloads681

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

WiflyDemoFeedbackComposer Developer Profile

davidaawow

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WiflyDemoFeedbackComposer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wiflydemofeedbackcomposer/ext/bootstrap.js/wp-content/plugins/wiflydemofeedbackcomposer/ext/bootstrap-icons.css/wp-content/plugins/wiflydemofeedbackcomposer/ext/bootstrap.css
Script Paths
/wp-content/plugins/wiflydemofeedbackcomposer/ext/bootstrap.js

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about WiflyDemoFeedbackComposer