
WP-Polls (with CubePoints) Security & Risk Analysis
wordpress.org/plugins/wp-polls-with-cubepointsWP-Polls (with CubePoints) is a modified version of [WP-Polls](http://wordpress.org/extend/plugins/wp-polls/ "WP-Polls") by Lester 'GaM …
Is WP-Polls (with CubePoints) Safe to Use in 2026?
Generally Safe
Score 100/100WP-Polls (with CubePoints) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The security posture of wp-polls-with-cubepoints v1.0 presents a mixed bag of concerning and positive indicators. While the plugin has no recorded vulnerability history, suggesting a historically stable codebase, the static analysis reveals significant potential weaknesses. A striking concern is the complete absence of prepared statements for any of the 73 SQL queries, making the plugin highly susceptible to SQL injection vulnerabilities. Furthermore, only 44% of output escaping is properly handled, indicating a risk of Cross-Site Scripting (XSS) vulnerabilities. The presence of two unsanitized paths in the taint analysis, one of which is rated as high severity, directly points to potential security flaws that require immediate attention.
On the positive side, the plugin demonstrates good practices by not exposing external HTTP requests and has no file operations that could be exploited. It also utilizes capability checks, which is a fundamental security measure. However, the lack of nonce checks on its entry points (shortcodes and cron events) is a notable oversight that could be leveraged for Cross-Site Request Forgery (CSRF) attacks. The bundled TinyMCE library, while common, could also introduce risks if it's an outdated version, though this is not explicitly detailed in the provided data. In conclusion, despite a clean vulnerability history, the extensive use of raw SQL, inadequate output escaping, and the identified high-severity taint flow, coupled with the absence of nonce checks, present a substantial risk that needs remediation.
Key Concerns
- Raw SQL queries without prepared statements
- High severity taint flow identified
- Low output escaping percentage
- Unsanitized paths in taint analysis
- Lack of nonce checks on entry points
WP-Polls (with CubePoints) Security Vulnerabilities
WP-Polls (with CubePoints) Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
WP-Polls (with CubePoints) Attack Surface
Shortcodes 2
WordPress Hooks 18
Scheduled Events 2
Maintenance & Trust
WP-Polls (with CubePoints) Maintenance & Trust
Maintenance Signals
Community Trust
WP-Polls (with CubePoints) Alternatives
WP-Polls
wp-polls
Adds an AJAX poll system to your WordPress blog. You can also easily add a poll into your WordPress's blog post/page.
Crowdsignal Dashboard – Polls, Surveys & more
polldaddy
Manage your Crowdsignal polls, surveys, quizzes, and ratings directly from the WordPress dashboard.
Poll Maker – Versus Polls, Anonymous Polls, Image Polls
poll-maker
Poll Maker is a FREE WordPress poll plugin that will let you create customizable and professional online polls and voting for your WordPress website.
Simply Polls
simply-polls
Add AJAX poll to your WordPress blog. You can use our polls on sidebars, posts and pages.
WP EASY POLL
wp-easy-poll
With WP EASY POLL user could add ajax based voting poll system to wordpress driven sites very easily.
WP-Polls (with CubePoints) Developer Profile
2 plugins · 20 total installs
How We Detect WP-Polls (with CubePoints)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-polls-with-cubepoints/polls-admin.css/wp-content/plugins/wp-polls-with-cubepoints/polls-js.js/wp-content/plugins/wp-polls-with-cubepoints/polls.css/wp-content/plugins/wp-polls-with-cubepoints/polls-vote.js/wp-content/plugins/wp-polls-with-cubepoints/polls-js.js/wp-content/plugins/wp-polls-with-cubepoints/polls-vote.jswp-polls-with-cubepoints/polls-admin.css?ver=wp-polls-with-cubepoints/polls-js.js?ver=wp-polls-with-cubepoints/polls.css?ver=wp-polls-with-cubepoints/polls-vote.js?ver=HTML / DOM Fingerprints
wp-pollspollbarpollq_idpollq_activepollq_questionpollq_stylepollq_timestamppollq_active+24 morepoll_ajax_url[poll id=[poll][poll vote=