WP Roadmap – Product Feedback Board Security & Risk Analysis

wordpress.org/plugins/wp-roadmap

WP Roadmap plugin is a perfect feedback and roadmap plugin tool that make adding roadmap and feedback easily to your WordPress website.

200 active installs v2.2.1 PHP 7.4+ WP 3.0.1+ Updated Dec 30, 2025
elementorfeedbackkanbanroadmap
98
A · Safe
CVEs total2
Unpatched0
Last CVEJun 19, 2025
Safety Verdict

Is WP Roadmap – Product Feedback Board Safe to Use in 2026?

Generally Safe

Score 98/100

WP Roadmap – Product Feedback Board has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Jun 19, 2025Updated 3mo ago
Risk Assessment

The "wp-roadmap" v2.2.1 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices in SQL query sanitization (84% prepared statements) and output escaping (96% properly escaped). The absence of external HTTP requests and a lack of bundled libraries also contribute to a more secure baseline. However, significant concerns arise from the large attack surface, particularly the 14 unprotected AJAX handlers which present a substantial risk of unauthorized actions or information disclosure. The presence of 'unserialize' is a red flag, and the 7 high-severity unsanitized taint flows indicate potential vulnerabilities that could be exploited for malicious purposes, despite the absence of critical-severity flows.

The plugin's vulnerability history, with 2 medium-severity CVEs related to SQL Injection and Cross-site Scripting, suggests a pattern of past weaknesses that attackers may still be aware of or attempt to exploit. Although there are no currently unpatched vulnerabilities, the existence of past issues, particularly in common vulnerability types, warrants caution. The recent last vulnerability date (June 2025) is unusual, but if it implies recent discovery of an unpatched issue, it would be a critical concern. Overall, while the plugin has strengths in data handling, the high number of unprotected entry points and high-severity taint flows represent the most immediate and significant risks.

Key Concerns

  • 14 unprotected AJAX handlers
  • 7 high severity unsanitized taint flows
  • 3 dangerous functions (unserialize)
  • 2 medium severity CVEs in history
Vulnerabilities
2

WP Roadmap – Product Feedback Board Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2025-52822medium · 6.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

WP Roadmap <= 2.1.3 - Authenticated (Contributor+) SQL Injection

Jun 19, 2025 Patched in 2.2.0 (203d)
CVE-2023-41128medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WP Roadmap <= 1.0.8 - Authenticated (Administrator+) Stored Cross-Site Scripting

Nov 23, 2023 Patched in 1.0.9 (61d)
Code Analysis
Analyzed Mar 16, 2026

WP Roadmap – Product Feedback Board Code Analysis

Dangerous Functions
3
Raw SQL Queries
18
92 prepared
Unescaped Output
15
389 escaped
Nonce Checks
18
Capability Checks
3
File Operations
1
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

unserialize$wp_general_setting_pages = isset($wp_general_setting['pages']) ? unserialize($wp_general_setting['padmin\view\general-settings.php:18
unserialize$matches = array_intersect(unserialize($options['pages']), $url_parts);public\class-rmpf-public.php:82
unserialize$matches = array_intersect(unserialize($options['pages']), $url_parts);public\class-rmpf-public.php:115

SQL Query Safety

84% prepared110 total queries

Output Escaping

96% escaped404 total outputs
Data Flows
7 unsanitized

Data Flow Analysis

19 flows7 with unsanitized paths
rmpf_status_delete (admin\class-rmpf-admin.php:363)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
14 unprotected

WP Roadmap – Product Feedback Board Attack Surface

Entry Points17
Unprotected14

AJAX Handlers 16

authwp_ajax_save_feedback_roadmap_settingsincludes\class-rmpf.php:138
authwp_ajax_update_feedback_roadmap_settingsincludes\class-rmpf.php:139
authwp_ajax_update_feedback_status_orderincludes\class-rmpf.php:140
authwp_ajax_delete_feedback_roadmap_settingsincludes\class-rmpf.php:141
authwp_ajax_save_feedback_roadmap_general_settingsincludes\class-rmpf.php:142
authwp_ajax_save_feedback_board_dataincludes\class-rmpf.php:143
authwp_ajax_delete_feedback_board_dataincludes\class-rmpf.php:144
authwp_ajax_reset_feedback_board_dataincludes\class-rmpf.php:145
authwp_ajax_edit_feedback_board_dataincludes\class-rmpf.php:146
authwp_ajax_wp_feedback_detailincludes\class-rmpf.php:147
authwp_ajax_wp_update_board_statusincludes\class-rmpf.php:148
authwp_ajax_wp_save_listincludes\class-rmpf.php:149
authwp_ajax_wp_like_button_insertincludes\class-rmpf.php:150
authwp_ajax_rmpf_bulk_delete_feedbackincludes\class-rmpf.php:154
authwp_ajax_rmpf_add_upvoteutils\rmpf_wiget_helper.php:101
noprivwp_ajax_rmpf_add_upvoteutils\rmpf_wiget_helper.php:102

Shortcodes 1

[rmpf_roadmap_widget] wp-roadmap-product-feedback.php:123
WordPress Hooks 24
actionadmin_headadmin\class-rmpf-admin.php:58
actionadmin_noticesadmin\class-rmpf-admin.php:65
actionadmin_noticesadmin\class-rmpf-admin.php:1383
actionrest_api_initincludes\api\class-rmpf-api.php:14
actionadmin_enqueue_scriptsincludes\class-rmpf.php:135
actionadmin_enqueue_scriptsincludes\class-rmpf.php:136
actionadmin_menuincludes\class-rmpf.php:137
actionadmin_menuincludes\class-rmpf.php:151
actionadmin_initincludes\class-rmpf.php:152
actionadmin_initincludes\class-rmpf.php:153
actionrmpf_process_scheduled_status_changesincludes\class-rmpf.php:155
actionwp_dashboard_setupincludes\class-rmpf.php:156
actionwp_enqueue_scriptsincludes\class-rmpf.php:169
actionwp_enqueue_scriptsincludes\class-rmpf.php:170
actionelementor/initincludes\class-rmpf.php:171
actionelementor/widgets/registerincludes\class-rmpf.php:172
actionwp_enqueue_scriptspublic\class-rmpf-public.php:155
filterrmpf_localize_roadmap_settingsstatic\rmpf-i18n.php:16
actionplugins_loadedwp-roadmap-product-feedback.php:53
actioninitwp-roadmap-product-feedback.php:76
actionwidgets_initwp-roadmap-product-feedback.php:108
actionwp_enqueue_scriptswp-roadmap-product-feedback.php:132
actionenqueue_block_editor_assetswp-roadmap-product-feedback.php:135
filterblock_categories_allwp-roadmap-product-feedback.php:162

Scheduled Events 1

rmpf_process_scheduled_status_changes
Maintenance & Trust

WP Roadmap – Product Feedback Board Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 30, 2025
PHP min version7.4
Downloads13K

Community Trust

Rating78/100
Number of ratings7
Active installs200
Developer Profile

WP Roadmap – Product Feedback Board Developer Profile

Iqonic Design

5 plugins · 17K total installs

74
trust score
Avg Security Score
93/100
Avg Patch Time
95 days
View full developer profile
Detection Fingerprints

How We Detect WP Roadmap – Product Feedback Board

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-roadmap/admin/js/rmpf-widget-block.js
Version Parameters
wp-roadmap/admin/js/rmpf-widget-block.js?ver=

HTML / DOM Fingerprints

CSS Classes
rmpf-widget-blocks
Data Attributes
data-rmpf-id
JS Globals
rmpf_base_varsSITE_URL
REST Endpoints
/wp-json/rmpf/v1/feedback
Shortcode Output
[rmpf_roadmap_widget]
FAQ

Frequently Asked Questions about WP Roadmap – Product Feedback Board