
Fyrebox Quizzes Security & Risk Analysis
wordpress.org/plugins/fyrebox-shortcodeCreate a quiz on the fyrebox.com website and display it easily in a post or on a tab.
Is Fyrebox Quizzes Safe to Use in 2026?
Use With Caution
Score 57/100Fyrebox Quizzes has 2 unpatched vulnerabilities. Evaluate alternatives or apply available mitigations.
The fyrebox-shortcode plugin v3.1 exhibits a mixed security posture. On the positive side, the static analysis reveals good practices such as 100% of SQL queries using prepared statements, a high percentage of properly escaped output (83%), and the presence of nonce and capability checks, suggesting an awareness of common WordPress security vulnerabilities. The attack surface is also minimal, with only one shortcode and no unprotected entry points identified in this scan.
However, the vulnerability history is a significant concern. The plugin has two known CVEs, both of which are currently unpatched. These past vulnerabilities include Cross-site Scripting (XSS) and Cross-Site Request Forgery (CSRF), which are critical for user data integrity and site security. The recurrence of these vulnerability types, combined with the fact that they remain unpatched, indicates a persistent weakness in the development or maintenance process. The presence of a file operation also warrants careful consideration, although no specific risks were flagged by the taint analysis in this instance.
In conclusion, while the plugin demonstrates some sound security practices in its current code, the history of unpatched vulnerabilities, particularly XSS and CSRF, presents a substantial risk. Users should be aware that the plugin's past security issues have not been addressed, potentially leaving them vulnerable to similar attacks. A strong recommendation would be to avoid this plugin or ensure that any future updates rigorously address and patch all known vulnerabilities.
Key Concerns
- Unpatched Medium Severity CVEs
- Past Cross-site Scripting (XSS) vulnerabilities
- Past Cross-Site Request Forgery (CSRF) vulnerabilities
- File operations present
- Moderate amount of unescaped output
Fyrebox Quizzes Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Fyrebox Quizzes <= 3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Fyrebox Quizzes <= 3.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Fyrebox Quizzes Code Analysis
Output Escaping
Data Flow Analysis
Fyrebox Quizzes Attack Surface
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
Fyrebox Quizzes Maintenance & Trust
Maintenance Signals
Community Trust
Fyrebox Quizzes Alternatives
Leadeo Lite
leadeo-lite
Get more visitors, leads and sales by showing various forms on top of your videos.
Hostinger Reach – AI-Powered Email Marketing for WordPress
hostinger-reach
Launch and grow your email marketing effortlessly with Hostinger Reach. Collect contacts, sync subscribers, and send emails – all in one, AI powered.
Jetpack CRM – Clients, Leads, Invoices, Billing, Email Marketing, & Automation
zero-bs-crm
The CRM for small businesses. Manage leads, invoicing, billing, email marketing, clients, contacts, quotes, automation. Works with WooCommerce too.
iConvert Promoter
iconvert-promoter
🚀 A powerful and dynamic WordPress popup toolkit to grow your email list, retain customers, and boost conversions.
Easy Notify Lite
easy-notify-lite
The best Popup Builder plugin to display image, video, notify or announcement with very ease and elegant.
Fyrebox Quizzes Developer Profile
1 plugin · 100 total installs
How We Detect Fyrebox Quizzes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/fyrebox-shortcode/css/bootstrap.min.css/wp-content/plugins/fyrebox-shortcode/css/bootstrap-toggle.min.css/wp-content/plugins/fyrebox-shortcode/js/popper.min.js/wp-content/plugins/fyrebox-shortcode/js/bootstrap.min.js/wp-content/plugins/fyrebox-shortcode/js/bootstrap-toggle.min.jshttps://www.fyrebox.com/javascripts/fyrebox.min.jsfyrebox-bootstrap.min.css?ver=bootstrap-toggle.min.css?ver=popper.min.js?ver=bootstrap.min.js?ver=bootstrap-toggle.min.js?ver=HTML / DOM Fingerprints
fyrebox_quizfyrebox_headerfyrebox-textfyreboxdata-giddata-oid__FYREBOX<div class="fyrebox_quiz" data-gid="