
WP Custom Voting Security & Risk Analysis
wordpress.org/plugins/wp-custom-votingThis plugin is meant for admin to bring the feature of VOTING to their posts or pages, like facebook post like.
Is WP Custom Voting Safe to Use in 2026?
Generally Safe
Score 85/100WP Custom Voting has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-custom-voting" v1.0 plugin exhibits a concerning security posture despite having no recorded vulnerabilities. The static analysis reveals two AJAX handlers, both lacking any form of authentication or capability checks. This represents a significant attack surface, as any unauthenticated user could potentially trigger these handlers. While the plugin uses prepared statements for SQL queries, the complete lack of output escaping on all seven identified output points is a critical flaw. This can lead to cross-site scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the website. The taint analysis shows a single flow with an unsanitized path, which, while not classified as critical or high severity in this analysis, warrants attention due to the overall lack of sanitization and escaping. The absence of any vulnerability history might suggest a lack of widespread exploitation or a relatively new plugin, but it does not negate the inherent risks identified in the code. The plugin's strengths lie in its use of prepared statements for database interactions and the absence of dangerous functions or file operations. However, the critical issues of unprotected AJAX endpoints and pervasive unescaped output create substantial security risks that need immediate attention.
Key Concerns
- Unprotected AJAX handlers
- All outputs unescaped
- Flow with unsanitized path
- Missing nonce checks on AJAX
- Missing capability checks on AJAX
WP Custom Voting Security Vulnerabilities
WP Custom Voting Release Timeline
WP Custom Voting Code Analysis
Output Escaping
Data Flow Analysis
WP Custom Voting Attack Surface
AJAX Handlers 2
WordPress Hooks 7
Maintenance & Trust
WP Custom Voting Maintenance & Trust
Maintenance Signals
Community Trust
WP Custom Voting Alternatives
Gp post Like
gp-post-like
Allow user add post like button above or below post content.
Kento Like Post
kento-like-post
Facebook Style like button for WordPress with like count and user thumbnails.
Kento Vote
kento-vote
Vote on Post and Display Who Voted via gravatar thumbnail.
WP PostVoting
wp-postvoting
"WP PostVoting" plugin allows visitors to vote on your blog's content with a widget of the most voted posts.
kk Star Ratings – Rate Post & Collect User Feedbacks
kk-star-ratings
kk Star Ratings allows blog visitors to involve and interact more effectively with your website by rating posts.
WP Custom Voting Developer Profile
1 plugin · 10 total installs
How We Detect WP Custom Voting
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-custom-voting/images/icon.png/wp-content/plugins/wp-custom-voting/images/dmitri-logo.png/wp-content/plugins/wp-custom-voting/images/hire-wordpress-guru.jpg/wp-content/plugins/wp-custom-voting/js/admin-script.js/wp-content/plugins/wp-custom-voting/css/admin-style.css/wp-content/plugins/wp-custom-voting/js/admin-script.jsHTML / DOM Fingerprints
wpcv-iconwpcv-leftwpcv-rightwpcv-textareawpcv-textarea-right