
WP Roadmap – Product Feedback Board Security & Risk Analysis
wordpress.org/plugins/wp-roadmapWP Roadmap plugin is a perfect feedback and roadmap plugin tool that make adding roadmap and feedback easily to your WordPress website.
Is WP Roadmap – Product Feedback Board Safe to Use in 2026?
Generally Safe
Score 98/100WP Roadmap – Product Feedback Board has a strong security track record. Known vulnerabilities have been patched promptly.
The "wp-roadmap" v2.2.1 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices in SQL query sanitization (84% prepared statements) and output escaping (96% properly escaped). The absence of external HTTP requests and a lack of bundled libraries also contribute to a more secure baseline. However, significant concerns arise from the large attack surface, particularly the 14 unprotected AJAX handlers which present a substantial risk of unauthorized actions or information disclosure. The presence of 'unserialize' is a red flag, and the 7 high-severity unsanitized taint flows indicate potential vulnerabilities that could be exploited for malicious purposes, despite the absence of critical-severity flows.
The plugin's vulnerability history, with 2 medium-severity CVEs related to SQL Injection and Cross-site Scripting, suggests a pattern of past weaknesses that attackers may still be aware of or attempt to exploit. Although there are no currently unpatched vulnerabilities, the existence of past issues, particularly in common vulnerability types, warrants caution. The recent last vulnerability date (June 2025) is unusual, but if it implies recent discovery of an unpatched issue, it would be a critical concern. Overall, while the plugin has strengths in data handling, the high number of unprotected entry points and high-severity taint flows represent the most immediate and significant risks.
Key Concerns
- 14 unprotected AJAX handlers
- 7 high severity unsanitized taint flows
- 3 dangerous functions (unserialize)
- 2 medium severity CVEs in history
WP Roadmap – Product Feedback Board Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
WP Roadmap <= 2.1.3 - Authenticated (Contributor+) SQL Injection
WP Roadmap <= 1.0.8 - Authenticated (Administrator+) Stored Cross-Site Scripting
WP Roadmap – Product Feedback Board Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Roadmap – Product Feedback Board Attack Surface
AJAX Handlers 16
Shortcodes 1
WordPress Hooks 24
Scheduled Events 1
Maintenance & Trust
WP Roadmap – Product Feedback Board Maintenance & Trust
Maintenance Signals
Community Trust
WP Roadmap – Product Feedback Board Alternatives
Timeline Widget For Elementor (Elementor Timeline, Vertical & Horizontal Timeline)
timeline-widget-addon-for-elementor
Highlight your company’s history, milestones, and key events directly inside Elementor using stunning vertical and horizontal timelines.
Changeloger – Release Notes & Changelog Manager
changeloger
The all-in-one changelog, release notes, public roadmap, and user feedback plugin for WordPress. Beautiful visual designs out of the box.
Simple Feature Requests Free – User Feedback Board
simple-feature-requests
Collect and manage user feedback using your existing WordPress website. Prioritize the product features important to you and your customers.
Roadmap
roadmap
Easily add a product roadmap and feedback form to your WordPress site, blog or members area. Keep your users up to date on your progress, product idea …
Product Roadmap
product-roadmap
Create public product roadmaps to share your vision, collect user feedback, and build products your customers actually want.
WP Roadmap – Product Feedback Board Developer Profile
5 plugins · 17K total installs
How We Detect WP Roadmap – Product Feedback Board
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-roadmap/admin/js/rmpf-widget-block.jswp-roadmap/admin/js/rmpf-widget-block.js?ver=HTML / DOM Fingerprints
rmpf-widget-blocksdata-rmpf-idrmpf_base_varsSITE_URL/wp-json/rmpf/v1/feedback[rmpf_roadmap_widget]