Description
Visual feedback and bug reporting, pinned right on the page
Send a client or teammate a review link. They click around your site and pin comments directly on the thing they mean – a headline, a button, a broken layout – with a screenshot attached if it helps. No account for them to create, no browser extension to install, no separate feedback tool to learn. “The button on the homepage looks off” becomes a pin your team can act on, whether it’s a design note or a bug report.
Why teams pick Vifee for website feedback
Pins that actually stay put
Most website feedback tools lose track of where a comment belongs the moment the page changes. Vifee anchors every pin with four fallback strategies – a CSS selector, an XPath, an element offset, and a document-percentage position – so pins survive a theme switch, a viewport resize, lazy-loaded content, and a full DOM rebuild. If the exact element is gone, the pin degrades gracefully instead of vanishing or jumping to the wrong spot.
Nothing leaves your server
Feedback, screenshots, and reviewer details are stored in your own WordPress database and a private, non-public uploads directory. Vifee makes no outbound requests, calls no third-party API, and sends no telemetry. For agencies working with public-sector, healthcare, or legal clients, “the data never leaves our server” is often a procurement requirement, not a nice-to-have.
A feedback widget, not a per-seat subscription
There’s no per-user or per-project pricing here. You install the feedback widget once and use it on as many review links, client sites, and reviewers as you need.
How the visual feedback workflow works
- A manager creates a review link from the Vifee admin screen.
- A reviewer who opens that link can leave pinned comments, screenshots and replies directly on the live site – no login required.
- Managers triage client feedback from a kanban-style admin screen: status, priority, filters and a detail view with the full reply thread and activity history.
A paid add-on is planned
A separate PRO add-on is planned for agencies managing feedback across multiple client sites. It will be entirely optional – nothing described above is disabled, watermarked, or held back in this free version to encourage an upgrade, and every feature here stays free, forever.
Multisite
Vifee keeps separate feedback for every site of a network. When the plugin is active on a site – individually or network-wide – that site gets its tables, keys, the manage_vifee_feedback capability for administrators and its daily maintenance on its first request, including sites added to the network later. Uninstalling honours each site’s own “delete all data” setting.
Privacy
Feedback may contain a display name, an optional private email address, technical browser data, replies and screenshots. Optional email addresses are encrypted at rest, using a dedicated encryption key generated on activation, and are never exposed to other reviewers.
Feedback is retained indefinitely by default; there is no automatic expiry, and older feedback must be removed manually from the Vifee admin screen. Review sessions expire automatically after 30 days.
Go to Vifee Settings to opt in to deleting all Vifee feedback, attachments and reviewer data when the plugin is uninstalled. This is disabled by default, so uninstalling the plugin normally leaves your feedback data in place.
This plugin supports the WordPress Tools Export/Erase Personal Data screens. They find guest reviewers by the email they left and signed-in authors by their WordPress account, and cover the profile, submitted feedback, replies and attachments. Erasure replaces the person’s text with a removal notice, clears browser details, deletes their screenshots and ends their review sessions.
Screenshots hide personal data before they leave the reviewer’s browser, so nobody has to remember to cover it. Passwords and elements with the data-vifee-mask attribute are always hidden; values typed into form fields are hidden by default. On Vifee Settings Privacy you can list more elements to hide by CSS selector, or hide all page text. The reviewer can cover anything else with the Hide area tool, which paints a solid block into the image: only the finished image is uploaded, never the original.
By default each new comment gets a screenshot of the visible part of the page, taken when the reviewer places the pin, with the pin painted on it. The reviewer sees it under the comment and can remove it before sending; it is masked exactly like a screenshot taken by hand. Switch it off on Vifee Settings Privacy.
Screenshots are stored under random file names in a private uploads subdirectory protected by .htaccess / web.config. On servers that ignore those files (nginx) the random names keep them unguessable; to keep them out of the web root entirely, define VIFEE_PRIVATE_DIR in wp-config.php with a directory outside it.
Credits
Bundled library
The review widget bundles html2canvas-pro (MIT licence, GPL-compatible: https://github.com/yorickshan/html2canvas-pro), a maintained fork of html2canvas, to render the on-page screenshot capture entirely in the reviewer’s browser. No image processing happens server-side and no third-party service is involved.
Screenshots




Installation
- Upload the plugin directory to
/wp-content/plugins/. - Activate Vifee Visual Feedback.
- Configure review access and data-retention preferences from the Vifee admin screens.
FAQ
-
Do reviewers need an account or a browser extension to leave feedback?
-
No. A reviewer opens the review link you send them and pins comments, screenshots and replies straight on the live page – no WordPress account, no browser extension, no separate app to install.
-
Can I use Vifee to collect bug reports from clients, not just design feedback?
-
Yes. Every pin has an issue type – Task or Bug – plus a priority and a workflow status, so a client reporting “this form is broken” and a client suggesting “make this button bigger” both land on the same triaged board instead of two different inboxes.
-
Can reviewers annotate a screenshot of the page instead of just leaving a comment?
-
Yes. A reviewer can attach a full-page or region screenshot to any pin and mark it up with shapes, arrows and a pixelation blur before sending – so a visual bug report carries the exact picture the manager needs, not just a text description.
-
Does the visual feedback widget work with Elementor, Divi, or any page builder?
-
Yes. The widget loads as a standard front-end script, independent of the theme or page builder that rendered the page, so it works the same way on Elementor, Divi, block-theme, or classic-theme sites.
-
Can I use Vifee for client feedback across multiple websites?
-
Yes – install it on as many WordPress sites as you like at no extra cost; there’s no per-site, per-user or per-project fee. Each installation keeps its own feedback separate from every other one (see “Who can see feedback?” below for how that works within a single site).
-
Does Vifee send any data outside my WordPress installation?
-
No. Feedback, screenshots and reviewer data are stored in your own database and a private, non-public uploads subdirectory. The plugin does not call any third-party service and does not send telemetry.
-
Who can see feedback?
-
Only WordPress users with the
manage_vifee_feedbackcapability (administrators, by default) and guests who used a valid, unexpired review link can see and submit feedback. The review widget is never shown to ordinary site visitors. The one exception: a page opened with a?vifee_token=that is unknown, expired or switched off shows a small “This review link no longer works” notice instead of the comment form, and that page view skips page caching. The notice reveals nothing about the site or its feedback and looks the same for an unknown and a dead link. Clean-mode links never show it. Archived feedback is visible only in the admin panel, never in the widget.Note for agencies serving multiple clients on one installation: reviewers authenticated through any valid review link share ONE feedback space per site – a reviewer for Client A can read threads opened for Client B. Scope installations (or use WordPress multisite) accordingly.
-
What happens to feedback when I uninstall the plugin?
-
By default, nothing – your database tables and any stored attachments are left in place so you can reinstall later without losing data. If you want uninstalling to permanently delete everything, enable that under Vifee Settings before you uninstall.
-
Does Vifee require any particular PHP extensions?
-
Yes: the GD extension (for screenshot processing) and the Fileinfo extension (for upload validation) are required in addition to PHP 8.1+. Most hosts enable both by default.
-
Does Vifee work on WordPress multisite networks?
-
Yes. Every site keeps its own feedback, review links and settings. Activate Vifee on single sites or network-wide: activating it on one site does not affect any other, and network-activating it sets up every site of the network, including sites added later (on their first request).
Reviews
There are no reviews for this plugin.
Contributors & Developers
“Vifee Visual Feedback – Client Website Review & Bug Reporting” is open source software. The following people have contributed to this plugin.
ContributorsTranslate “Vifee Visual Feedback – Client Website Review & Bug Reporting” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
1.3.0
- [Feature] Every new comment gets a screenshot of the visible part of the page, taken as the pin is placed, with the pin painted on it. It appears under the comment, where the reviewer can remove it before sending, and is masked like any other screenshot. Switch it off on Settings Privacy.
- [Feature] Overlapping pins merge into one marker that lists its comments, and pins show when an item is done.
- [Changed] Pins on the page are plain circles in the colour of their priority.
- [Changed] The review link greeting no longer covers the page: a reviewer can look around first and gives a name only when adding a comment. A review link that is unknown, expired or switched off says “This review link no longer works” instead of showing nothing.
- [Changed] On desktop the comment form opens beside its pin, and a temporary pin marks the spot while the comment is written. A sent comment is confirmed, and one lost to a dropped connection can be sent again.
- [Changed] Comments and replies share one editor, with the formatting toolbar always at hand.
- [Changed] Area selection finishes when the mouse or finger is released and can be cleared; thumbnails are framed on the pin.
- [Changed] The sidebar no longer blocks the page, the open comment in it is clearly outlined, text on brand-coloured buttons stays readable whatever the colour, and on phones every control is at least 44 px and text at least 11 px.
- [Changed] Status and priority labels in the admin panel have more contrast.
- [Changed] For add-ons: feedback takes three images and one other attachment registered through
vifee_attachment_sources, andvifee_bootstrap_datareceives the review link. Replies take images only. - [Fixed] A cancelled comment no longer carries its screenshots over to the next pin.
- [Fixed] Pressing bold, italic or code with nothing selected no longer leaves stray asterisks or backticks in the admin panel.
- [Fixed] Keyboard pin placement skips the pins already on the page.
1.2.0
- [Feature] Screenshots hide personal data before they leave the reviewer’s browser, so nobody has to remember to cover it. Values typed into form fields are hidden by default; passwords and elements with the
data-vifee-maskattribute always are. The new Settings Privacy tab adds CSS selectors for more elements to hide and an option to hide all page text. - [Changed] The blur tools in the screenshot editor are now Hide area tools that paint a solid block: pixelated text can be pieced back together, a solid block cannot.
- [Fixed] Elements with the
data-vifee-maskattribute keep their size in screenshots instead of collapsing to an empty line.
1.1.2
- [Fixed] Adding feedback and screenshots works on hosting whose firewall rejects requests containing paths such as
/html[1]or image uploads sent as raw data. When a firewall still blocks a request, the widget says so instead of “The server returned an invalid response”. - [Fixed] A reviewer whose link covers a single page is told so, with a link to that page, instead of writing a comment on another page that then fails with “Feedback does not exist”.
- [Fixed] On touch screens, placing a pin on a link or button no longer opens the link or presses the button.
- [Fixed] On phones, the annotation toolbar fits the screen with finger-sized buttons and highlights the chosen tool right away, area selection works by dragging and can be cancelled, and the hints no longer mention keys a touch screen does not have.
1.1.1
- [Feature] A single-page review link can point at the homepage: the page field accepts
/, and a Homepage button fills it in. - [Fixed] A single-page review link opens the page it is limited to instead of the homepage.
- [Fixed] Screenshots work on themes that use modern CSS colours such as
color-mix(), where the capture failed with “Attempting to parse an unsupported color function”. The widget now bundles html2canvas-pro, a maintained fork of html2canvas. - [Fixed] The widget keeps its own fonts and colours on themes whose CSS reaches into it, instead of showing serif text in places.
- [Fixed] A page left open for more than a day keeps working: when the security token expires, the widget fetches a fresh one, also for loading screenshots, instead of failing every action until the page is reloaded.
- [Fixed] In browsers older than mid-2023 the widget listed the whole site’s feedback on every page.
- [Fixed] Sites that change the address while you browse (filters, section links) no longer reload the feedback and close the open comment.
- [Fixed] Priorities and issue types added by an add-on appear in the comment form, sort in the right order and keep their colour in the pin popover. A custom brand colour covers every accent of the widget.
- [Fixed] A WordPress user who changes their display name no longer signs new feedback with the old one.
- [Fixed] On multisite, activating the plugin network-wide sets up every site again after a network-wide deactivation.
- [Fixed] Upgrading from an early version no longer widens a column past the database row limit on some hosts.
- [Fixed] Notification e-mails sent after the response no longer stop other plugins from finishing their own end-of-request work.
- [Fixed] The board filters show priorities added by an add-on, and the people search on Settings Access no longer shows outdated results.
- [Performance] The widget watches the page once for all pins, and not at all on a page without pins.
- [Performance] The widget’s feedback list is always limited to one page and capped, so a request can no longer load every item on the site.
- [Performance] Fewer database queries: a reviewer’s session is looked up once per request, reply attachments load in one query per thread, the open-feedback count in the admin bar is cached for five minutes, and settings read on almost every request are autoloaded.
1.1.0
- [Feature] Settings Access: choose which WordPress roles get Client access, and give individual people Client, Team or Manager access. Clients see all feedback, reply and change its status; Team members work on feedback like an administrator; Managers also create review links. People with access use the widget on your site without a review link.
- [Feature] The feedback board refreshes itself while it is open, so new feedback and changes made by others appear without reloading the page.
- [Changed] Export and settings are now for administrators only, and review links need Manager access. A role you gave the feedback capability to by hand keeps Team access until you choose roles on Settings Access.
- [Fixed] Buttons, fields and dropdowns in the admin panel all have the same height.
1.0.5
- [Fixed] A screenshot of the visible part of the page shows what is on screen, not the top of the page, when the page is scrolled.
- [Fixed] Screenshots place text exactly where it appears on the page, including on themes that display images as blocks, and centred layouts are no longer shifted sideways by half the scrollbar width.
- [Feature] The WordPress admin bar shows feedback managers how many feedback items are open, with a link to the board.
- [Feature] Compatible add-ons, such as the client portal in Vifee PRO, can let your client reply to feedback, move it between statuses and view its screenshots outside the widget, under the client’s own name.
1.0.4
- [Fixed] Archived feedback is visible only in the admin panel: the widget shows neither its pins nor its threads, and reviewers can no longer read, reply to, edit or download attachments from archived items.
- [Feature] Reply to feedback from the details panel on the manager board (Markdown supported; Ctrl/Cmd+Enter sends). The thread author is notified as for replies from the widget.
1.0.3
- [Fixed] The widget shows every pin on a page instead of the newest 50.
- [Fixed] The review-link screen lists every link instead of the newest 100, 50 at a time with a “Show more” button.
- [Fixed] Pages whose query parameters differ only in letter case no longer lose their pins.
- [Fixed] Confirming an unsubscribe shows a page instead of raw JSON.
- [Fixed] Reply notifications to guests no longer link to the admin board they cannot open.
- [Fixed] Impossible due dates such as 31 February are rejected instead of rolling into March.
- [Fixed] A view-only review link no longer offers replying or editing that the server then refuses.
- [Fixed] On multisite every site gets the capability, scheduled tasks and keys it needs; uninstalling cleans every site.
- [Feature] Revoked review links can be deleted permanently.
- [Changed] Review links expired for more than 90 days are deleted with their sessions by the daily maintenance.
1.0.2
- [Security] Attachment files are stored under a random name instead of their public identifier, so a server that ignores
.htaccess(nginx) no longer serves a screenshot to anyone who has seen its id. Existing files are renamed in the background after the upgrade. The newVIFEE_PRIVATE_DIRconstant moves storage outside the web root. - [Security] A reviewer can keep at most 10 unsent attachments at a time.
- [Security] Failed review-link activations are limited per visitor, valid ones to 10 per 15 minutes per link, so reviewers behind one proxy or CDN address no longer lock each other out.
- [Security] Personal-data export and erasure also cover feedback written by signed-in WordPress users; erasure clears browser details and ends the reviewer’s sessions.
- [Performance] Notification e-mails are sent after the response, so posting feedback no longer waits for the mail server.
- [Performance] One fewer database query on every page load, and cheaper reply counts.
1.0.1
- [Security] REST endpoints no longer treat every signed-in WordPress account as a reviewer. Reading feedback, posting it, replying and uploading attachments now require either the
manage_vifee_feedbackcapability (administrators, by default) or an active review-link session. Before this release, on a site that lets visitors register, any signed-in account could read every feedback item and screenshot and add its own – without a review link and without being a feedback manager. The widget never offered those actions to such an account, but the REST API accepted them. - [Fixed] A reviewer who happens to also be signed in to WordPress under an unrelated account is now served the widget and works as the guest their review link makes them, instead of being shut out.
- [Fixed] Opening a review link with a name made only of spaces returned a server error instead of telling the reviewer the name is required.
- [Fixed] Comment or reply text containing control characters could break the notification e-mail and turn a comment that had in fact been saved into an error response.
- [Fixed] A notification or add-on listener that fails no longer turns a saved comment into an error response.
- [Fixed] Fresh installations no longer replay historical database migrations. One of them re-created a column wide enough to exceed the database row limit, which could leave the schema incomplete on some hosts.
- [Fixed] The request rate limiter no longer stops counting on object-cache backends without an atomic increment, and no longer writes a log line on every request there.
- [Fixed] Two simultaneous first requests could each generate a different encryption key and the loser’s key was kept, permanently invalidating every review link and stored reviewer address derived from it.
- [Fixed] The daily retention sweep now clears its whole backlog instead of at most 100 rows a day, so expired sessions and abandoned uploads can no longer pile up faster than they are removed.
- [Fixed] REST clients that authenticate with Application Passwords (rather than a browser session) can now write.
- [Performance] The feedback list no longer runs three unindexed text comparisons per row when no search term is given, and the table gained an index for the default sort order.
- [Performance] Editing or deleting a feedback item costs one database read instead of four, and the review-link screen no longer queries once per row.
- [Performance] Private attachment storage is prepared only when a request actually reads or writes a file, instead of on every REST request the site serves.
- [Feature] New
vifee_admin_feedback_filtersfilter: an add-on can narrow the manager board by handing it auuidSourcedescriptor, resolved as a SQL subquery against the add-on’s own table. - [Changed] Notification e-mails are now sent as HTML with a plain-text alternative: the comment sits in a quoted block, the page, priority and status are listed as details, and a button opens the feedback board. Nothing in the message is loaded from the network – no images, no web fonts, no tracking pixel – so reading one tells the sender nothing.
- [Changed] The
uuidIn/uuidNotInrequest parameters on the manager feedback endpoint are gone, replaced by the filter above – they required shipping a list of identifiers over HTTP. - [Changed] Two tables created but never used by any release are dropped on upgrade.
1.0.0
- First public release.
