
WP EASY POLL Security & Risk Analysis
wordpress.org/plugins/wp-easy-pollWith WP EASY POLL user could add ajax based voting poll system to wordpress driven sites very easily.
Is WP EASY POLL Safe to Use in 2026?
Generally Safe
Score 85/100WP EASY POLL has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-easy-poll plugin v1.0 exhibits a concerning security posture due to several critical weaknesses. The static analysis reveals a significant attack surface with two AJAX handlers lacking authentication checks, exposing them to unauthorized access. Furthermore, the complete absence of prepared statements for all SQL queries and the lack of any output escaping are major red flags, making the plugin highly susceptible to SQL injection and cross-site scripting (XSS) vulnerabilities. The fact that 100% of SQL queries are not using prepared statements and 0% of outputs are properly escaped indicates a severe lack of basic security practices in the codebase. While the plugin has no recorded vulnerability history (CVEs), this does not negate the immediate risks identified in the code itself. The lack of any reported vulnerabilities might be due to the plugin's obscurity or a lack of thorough security auditing in the past. The current state of the code suggests a high likelihood of exploitation if these vulnerabilities are present. In conclusion, despite a clean vulnerability history, the raw code analysis reveals profound security deficiencies that require immediate attention. The unprotected entry points, insecure SQL handling, and unescaped output collectively present a significant risk to any WordPress site using this plugin.
Key Concerns
- AJAX handlers without authentication
- SQL queries without prepared statements
- Outputs not properly escaped
- No nonce checks on AJAX
- No capability checks
- Use of create_function
WP EASY POLL Security Vulnerabilities
WP EASY POLL Release Timeline
WP EASY POLL Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
WP EASY POLL Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 15
Maintenance & Trust
WP EASY POLL Maintenance & Trust
Maintenance Signals
Community Trust
WP EASY POLL Alternatives
WP-Polls
wp-polls
Adds an AJAX poll system to your WordPress blog. You can also easily add a poll into your WordPress's blog post/page.
WP-Polls (with CubePoints)
wp-polls-with-cubepoints
WP-Polls (with CubePoints) is a modified version of [WP-Polls](http://wordpress.org/extend/plugins/wp-polls/ "WP-Polls") by Lester 'GaM …
Poll And Vote System
poll-and-vote-system
Poll system in WordPress block enabled. Add a poll to post throw shortcode and get all poll throw rest API.
Crowdsignal Dashboard – Polls, Surveys & more
polldaddy
Manage your Crowdsignal polls, surveys, quizzes, and ratings directly from the WordPress dashboard.
Democracy Poll
democracy-poll
WordPress polls plugin with multiple-choice, custom answers, cache compatibility, widgets, and shortcodes.
WP EASY POLL Developer Profile
1 plugin · 10 total installs
How We Detect WP EASY POLL
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-easy-poll/style_admin_back.cssHTML / DOM Fingerprints
image_barpreloader_registerid="poll_class_tuh"id="registerid="preloader_id="poll_ajax_object