Fyrebox Quizzes Security & Risk Analysis

wordpress.org/plugins/fyrebox-shortcode

Create a quiz on the fyrebox.com website and display it easily in a post or on a tab.

100 active installs v3.1 PHP + WP 2.6.0+ Updated Jul 13, 2025
email-listfyreboxlead-generationmarketingquizzes
57
C · Use Caution
CVEs total2
Unpatched2
Last CVEJun 19, 2025
Safety Verdict

Is Fyrebox Quizzes Safe to Use in 2026?

Use With Caution

Score 57/100

Fyrebox Quizzes has 2 unpatched vulnerabilities. Evaluate alternatives or apply available mitigations.

2 known CVEs 2 unpatched Last CVE: Jun 19, 2025Updated 8mo ago
Risk Assessment

The fyrebox-shortcode plugin v3.1 exhibits a mixed security posture. On the positive side, the static analysis reveals good practices such as 100% of SQL queries using prepared statements, a high percentage of properly escaped output (83%), and the presence of nonce and capability checks, suggesting an awareness of common WordPress security vulnerabilities. The attack surface is also minimal, with only one shortcode and no unprotected entry points identified in this scan.

However, the vulnerability history is a significant concern. The plugin has two known CVEs, both of which are currently unpatched. These past vulnerabilities include Cross-site Scripting (XSS) and Cross-Site Request Forgery (CSRF), which are critical for user data integrity and site security. The recurrence of these vulnerability types, combined with the fact that they remain unpatched, indicates a persistent weakness in the development or maintenance process. The presence of a file operation also warrants careful consideration, although no specific risks were flagged by the taint analysis in this instance.

In conclusion, while the plugin demonstrates some sound security practices in its current code, the history of unpatched vulnerabilities, particularly XSS and CSRF, presents a substantial risk. Users should be aware that the plugin's past security issues have not been addressed, potentially leaving them vulnerable to similar attacks. A strong recommendation would be to avoid this plugin or ensure that any future updates rigorously address and patch all known vulnerabilities.

Key Concerns

  • Unpatched Medium Severity CVEs
  • Past Cross-site Scripting (XSS) vulnerabilities
  • Past Cross-Site Request Forgery (CSRF) vulnerabilities
  • File operations present
  • Moderate amount of unescaped output
Vulnerabilities
2

Fyrebox Quizzes Security Vulnerabilities

CVEs by Year

2 CVEs in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2025-50035medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Fyrebox Quizzes <= 3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Jun 19, 2025Unpatched
CVE-2025-25125medium · 6.1Cross-Site Request Forgery (CSRF)

Fyrebox Quizzes <= 3.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting

Feb 3, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Fyrebox Quizzes Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
34 escaped
Nonce Checks
2
Capability Checks
1
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

83% escaped41 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
fyrebox_shortcode_options (fyrebox-shortcode.php:165)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Fyrebox Quizzes Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[fyrebox] fyrebox-shortcode.php:23
WordPress Hooks 7
actionplugins_loadedfyrebox-shortcode.php:22
actionadmin_enqueue_scriptsfyrebox-shortcode.php:47
actionwp_footerfyrebox-shortcode.php:57
actionadmin_menufyrebox-shortcode.php:105
actionadmin_initfyrebox-shortcode.php:108
actionadmin_enqueue_scriptsfyrebox-shortcode.php:163
actionadmin_footerfyrebox-shortcode.php:428
Maintenance & Trust

Fyrebox Quizzes Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJul 13, 2025
PHP min version
Downloads7K

Community Trust

Rating100/100
Number of ratings2
Active installs100
Developer Profile

Fyrebox Quizzes Developer Profile

CyrilG

1 plugin · 100 total installs

64
trust score
Avg Security Score
57/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Fyrebox Quizzes

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/fyrebox-shortcode/css/bootstrap.min.css/wp-content/plugins/fyrebox-shortcode/css/bootstrap-toggle.min.css/wp-content/plugins/fyrebox-shortcode/js/popper.min.js/wp-content/plugins/fyrebox-shortcode/js/bootstrap.min.js/wp-content/plugins/fyrebox-shortcode/js/bootstrap-toggle.min.js
Script Paths
https://www.fyrebox.com/javascripts/fyrebox.min.js
Version Parameters
fyrebox-bootstrap.min.css?ver=bootstrap-toggle.min.css?ver=popper.min.js?ver=bootstrap.min.js?ver=bootstrap-toggle.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
fyrebox_quizfyrebox_headerfyrebox-textfyrebox
Data Attributes
data-giddata-oid
JS Globals
__FYREBOX
Shortcode Output
<div class="fyrebox_quiz" data-gid="
FAQ

Frequently Asked Questions about Fyrebox Quizzes