
YOP Poll Security & Risk Analysis
wordpress.org/plugins/yop-pollUse a full option polling solution to get the answers you need. YOP Poll is the perfect, easy to use poll plugin for your WordPress site.
Is YOP Poll Safe to Use in 2026?
Generally Safe
Score 92/100YOP Poll has a strong security track record. Known vulnerabilities have been patched promptly.
The yop-poll plugin v6.5.40 exhibits a mixed security posture. While it demonstrates good practices in many areas, including a high percentage of properly escaped output and SQL queries using prepared statements, several concerning aspects are evident. The static analysis reveals a significant attack surface with 10 unprotected AJAX handlers, which could be exploited to bypass authorization checks. Furthermore, the presence of 2 critical severity taint flows with unsanitized paths indicates potential for severe vulnerabilities if these flows are reachable by attackers. The plugin's vulnerability history is also a notable concern, with 14 known CVEs, including one high severity vulnerability. While there are currently no unpatched vulnerabilities, the recurring pattern of vulnerabilities like missing authorization and cross-site scripting suggests a need for more robust security development lifecycle practices. The plugin's strengths lie in its efforts towards secure coding, but the identified unprotected entry points and taint analysis findings necessitate careful attention.
Key Concerns
- Unprotected AJAX handlers
- High severity taint flows
- Known vulnerability history (1 High)
- Dangerous function (unserialize)
YOP Poll Security Vulnerabilities
CVEs by Year
Severity Breakdown
14 total CVEs
YOP Poll <= 6.5.38 - Missing Authorization
YOP Poll <= 6.5.37 - Unauthenticated Stored Cross-Site Scripting
YOP Poll <= 6.5.26 - Race Condition to Vote Manipulation
YOP Poll <= 6.5.28 - Reusable Captcha via validateImage
YOP Poll <= 6.4.2 - IP Spoofing via X-Forwarded-For header
YOP Poll <= 6.3.4 - Author+ Stored Cross-Site Scripting
YOP Poll <= 6.3.0 - Author+ Stored Cross-Site Scripting via Preview Module
YOP Poll <= 6.3.0 - Author+ Stored Cross-Site Scripting via Options Module
YOP Poll <= 6.2.7 - Unauthenticated Stored Cross-Site Scripting
YOP Poll <= 6.1.4 - Authenticated Stored Cross-Site Scripting
YOP Poll <= 6.1.1 - Reflected Cross-Site Scripting
YOP Poll <= 6.0.2 - Reflected Cross-Site Scripting via poll_id Parameter
YOP Poll <= 5.8.0 - Reflected Cross-Site Scripting
YOP Poll <= 5.7.3 - Reflected Cross-Site Scripting
YOP Poll Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
YOP Poll Attack Surface
AJAX Handlers 38
Shortcodes 3
WordPress Hooks 17
Scheduled Events 1
Maintenance & Trust
YOP Poll Maintenance & Trust
Maintenance Signals
Community Trust
YOP Poll Alternatives
Poll Maker – Versus Polls, Anonymous Polls, Image Polls
poll-maker
Poll Maker is a FREE WordPress poll plugin that will let you create customizable and professional online polls and voting for your WordPress website.
Simple Poll
smp-simple-poll
The Simple Poll is a voting poll system into your post, pages and everywhere in website by just a shortcode. Add poll system to your post by placing s …
TS Poll – Survey, Versus Poll, Image Poll, Video Poll
poll-wp
Poll plugin is a responsive and customizable for WordPress. Poll will help you more easily create powerful poll, image & video poll, vote, results.
Better WordPress Polldaddy Polls
bwp-polldaddy
Helps you add Polldaddy Polls to your WordPress website easily.
Crowdsignal Forms
crowdsignal-forms
The Crowdsignal Forms plugin allows you to create and manage polls right from within the block editor.
YOP Poll Developer Profile
1 plugin · 10K total installs
How We Detect YOP Poll
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.