Interact: Embed A Quiz On Your Site Security & Risk Analysis

wordpress.org/plugins/interact-quiz-embed

Use this plugin to generate a shortcode to embed your Interact Quiz, Poll, or Giveaway into your WordPress site.

3K active installs v3.2 PHP + WP 3.0.1+ Updated Sep 30, 2025
embedgiveawayinteractpollquiz
98
A · Safe
CVEs total2
Unpatched0
Last CVESep 22, 2025
Safety Verdict

Is Interact: Embed A Quiz On Your Site Safe to Use in 2026?

Generally Safe

Score 98/100

Interact: Embed A Quiz On Your Site has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Sep 22, 2025Updated 6mo ago
Risk Assessment

The static analysis of 'interact-quiz-embed' v3.2 reveals a generally strong security posture. The plugin demonstrates excellent adherence to secure coding practices, with all SQL queries using prepared statements, all output properly escaped, and no dangerous functions or file operations identified. The absence of external HTTP requests and a clean taint analysis with no unsanitized paths are significant strengths, indicating a low risk of direct code injection or data leakage through these vectors. Furthermore, the presence of nonce checks on the identified entry points is commendable.

However, a notable concern arises from the plugin's vulnerability history. Two medium-severity CVEs have been recorded, specifically Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS). While the data indicates no currently unpatched vulnerabilities, the recurring nature of these common vulnerability types suggests potential oversights in input validation or state management that may have led to past issues. The last reported vulnerability date, 2025-09-22, is in the future, which is likely a data error or placeholder but still highlights the importance of ongoing vigilance.

In conclusion, 'interact-quiz-embed' v3.2 exhibits robust technical security in its current implementation, with a well-managed attack surface and secure coding practices. The primary area of caution stems from its past vulnerability history, particularly the types of issues encountered. This suggests that while the code may be clean now, a history of CSRF and XSS implies that the developers should maintain a heightened awareness of these common attack vectors to prevent future recurrences.

Key Concerns

  • Two medium severity CVEs in history
Vulnerabilities
2

Interact: Embed A Quiz On Your Site Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2025-58675medium · 4.3Cross-Site Request Forgery (CSRF)

Interact: Embed A Quiz On Your Site <= 3.1 - Cross-Site Request Forgery

Sep 22, 2025 Patched in 3.2 (11d)
CVE-2023-5659medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Interact: Embed A Quiz On Your Site <= 3.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

Nov 3, 2023 Patched in 3.1 (81d)
Code Analysis
Analyzed Mar 16, 2026

Interact: Embed A Quiz On Your Site Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
24 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped24 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
interact_option_page (interact-quiz-embed.php:169)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Interact: Embed A Quiz On Your Site Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[interact-quiz] interact-quiz-embed.php:61
[interact] interact-quiz-embed.php:123
WordPress Hooks 3
actionwp_headinteract-quiz-embed.php:145
actionwp_enqueue_scriptsinteract-quiz-embed.php:159
actionadmin_menuinteract-quiz-embed.php:302
Maintenance & Trust

Interact: Embed A Quiz On Your Site Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 30, 2025
PHP min version
Downloads70K

Community Trust

Rating92/100
Number of ratings11
Active installs3K
Developer Profile

Interact: Embed A Quiz On Your Site Developer Profile

tryinteract

1 plugin · 3K total installs

87
trust score
Avg Security Score
98/100
Avg Patch Time
46 days
View full developer profile
Detection Fingerprints

How We Detect Interact: Embed A Quiz On Your Site

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/interact-quiz-embed/interact-embed.js
Script Paths
https://i.tryinteract.com/promotions/init.js

HTML / DOM Fingerprints

CSS Classes
interact-embed
Data Attributes
id="interact-ref"appIdhostauto_resizemobile+1 more
JS Globals
InteractAppi_promo
Shortcode Output
[interact-quiz[interact
FAQ

Frequently Asked Questions about Interact: Embed A Quiz On Your Site