Codevery Quiz Security & Risk Analysis

wordpress.org/plugins/codevery-quiz

Create engaging quizzes on your WordPress site and offer incentives for high scores. Users can earn discount coupons based on their quiz results.

10 active installs v1.1.2 PHP 7.4+ WP 5.0+ Updated Nov 13, 2025
coupondiscountpointsquestionsquiz
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Codevery Quiz Safe to Use in 2026?

Generally Safe

Score 100/100

Codevery Quiz has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The 'codevery-quiz' plugin version 1.1.2 exhibits a generally strong security posture based on the static analysis. The complete absence of known CVEs and the fact that all SQL queries utilize prepared statements are positive indicators. Furthermore, the plugin demonstrates good practice by implementing nonce and capability checks on its AJAX handlers and having a very high percentage of properly escaped output.

However, a potential concern arises from the taint analysis, which identified one flow with an unsanitized path. While no critical or high severity taint issues were found, this single instance suggests a potential avenue for exploitation if that path handles user-supplied input without proper sanitization. The presence of one file operation also warrants attention, as such operations can be risky if not implemented securely.

Overall, the plugin appears to be well-developed from a security perspective, with a robust history of no reported vulnerabilities. The strengths in prepared statements, output escaping, and authentication checks significantly outweigh the identified minor concerns. Nevertheless, the single unsanitized path flow should be investigated to ensure it doesn't lead to a security vulnerability.

Key Concerns

  • Flow with unsanitized paths detected
  • One file operation detected
Vulnerabilities
None known

Codevery Quiz Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Codevery Quiz Release Timeline

v1.1.2Current
v1.1.1
v1.1.0
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

Codevery Quiz Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
3 prepared
Unescaped Output
13
305 escaped
Nonce Checks
9
Capability Checks
5
File Operations
1
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

100% prepared3 total queries

Output Escaping

96% escaped318 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

4 flows1 with unsanitized paths
cquiz_email_list_admin_page (includes\admin\class-codevery-quiz-email-list.php:43)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Codevery Quiz Attack Surface

Entry Points9
Unprotected0

AJAX Handlers 7

authwp_ajax_cquiz_get_questionsincludes\admin\codevery-quiz-admin.php:58
authwp_ajax_cquiz_add_new_questionincludes\admin\codevery-quiz-admin.php:59
authwp_ajax_cquiz_send_coupon_to_userincludes\public\class-codevery-quiz-public.php:62
noprivwp_ajax_cquiz_send_coupon_to_userincludes\public\class-codevery-quiz-public.php:63
authwp_ajax_cquiz_add_coupon_to_databaseincludes\public\class-codevery-quiz-public.php:65
noprivwp_ajax_cquiz_add_coupon_to_databaseincludes\public\class-codevery-quiz-public.php:66
authwp_ajax_cquiz_export_email_listincludes\public\class-codevery-quiz-public.php:68

Shortcodes 2

[codevery_quiz] includes\public\class-codevery-quiz-public.php:57
[codevery_quiz_certificate] includes\public\class-codevery-quiz-public.php:58
WordPress Hooks 16
actionplugins_loadedcodevery-quiz.php:40
actionadmin_menuincludes\admin\class-codevery-quiz-email-list.php:19
actionadmin_menuincludes\admin\codevery-quiz-admin.php:47
actionadmin_enqueue_scriptsincludes\admin\codevery-quiz-admin.php:49
actionadmin_enqueue_scriptsincludes\admin\codevery-quiz-admin.php:50
actionadmin_initincludes\admin\codevery-quiz-admin.php:52
actionsave_postincludes\admin\codevery-quiz-admin.php:53
actionadmin_initincludes\admin\codevery-quiz-admin.php:55
actionadmin_action_cquiz_modal_windowincludes\admin\codevery-quiz-admin.php:62
actioninitincludes\cquiz-post-types.php:17
filtermanage_quiz_question_posts_columnsincludes\cquiz-post-types.php:21
actionmanage_quiz_question_posts_custom_columnincludes\cquiz-post-types.php:22
actionadmin_menuincludes\cquiz-post-types.php:26
filteruse_block_editor_for_post_typeincludes\cquiz-post-types.php:28
actionwp_enqueue_scriptsincludes\public\class-codevery-quiz-public.php:51
actionwp_enqueue_scriptsincludes\public\class-codevery-quiz-public.php:52
Maintenance & Trust

Codevery Quiz Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 13, 2025
PHP min version7.4
Downloads3K

Community Trust

Rating100/100
Number of ratings4
Active installs10
Developer Profile

Codevery Quiz Developer Profile

Codevery LLC

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Codevery Quiz

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/codevery-quiz/assets/css/cquiz-admin.css/wp-content/plugins/codevery-quiz/assets/css/select2.min.css/wp-content/plugins/codevery-quiz/assets/js/select2.min.js/wp-content/plugins/codevery-quiz/assets/js/cquiz-repeater.js/wp-content/plugins/codevery-quiz/assets/js/cquiz-repeater.min.js/wp-content/plugins/codevery-quiz/assets/js/cquiz-admin.js/wp-content/plugins/codevery-quiz/assets/js/cquiz-admin.min.js
Script Paths
/wp-content/plugins/codevery-quiz/assets/js/select2.min.js/wp-content/plugins/codevery-quiz/assets/js/cquiz-repeater.js/wp-content/plugins/codevery-quiz/assets/js/cquiz-repeater.min.js/wp-content/plugins/codevery-quiz/assets/js/cquiz-admin.js/wp-content/plugins/codevery-quiz/assets/js/cquiz-admin.min.js
Version Parameters
codevery-quiz?ver=cquiz-admin.css?ver=select2.min.css?ver=select2.min.js?ver=cquiz-repeater.js?ver=cquiz-repeater.min.js?ver=cquiz-admin.js?ver=cquiz-admin.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
cquiz-admin-wrapcquiz-wrap
Data Attributes
data-quiz-iddata-question-iddata-user-iddata-option-iddata-result-id
JS Globals
quizParams
FAQ

Frequently Asked Questions about Codevery Quiz