
Max Stats Table for WP Pro Quiz Security & Risk Analysis
wordpress.org/plugins/max-stats-table-for-wp-pro-quizThis plugin reqires the WP Pro Quiz plugin by Julius Fischer (https://wordpress.org/plugins/wp-pro-quiz/). The plugin will create a page very similar …
Is Max Stats Table for WP Pro Quiz Safe to Use in 2026?
Generally Safe
Score 85/100Max Stats Table for WP Pro Quiz has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'max-stats-table-for-wp-pro-quiz' plugin v3.2.1 exhibits a mixed security posture. On the positive side, there are no recorded vulnerabilities in its history, which is a strong indicator of good past development and maintenance. Furthermore, the plugin boasts a limited attack surface with only one shortcode and no unprotected AJAX handlers or REST API routes. There are also no concerning code signals like dangerous functions, file operations, or external HTTP requests.
However, there are significant concerns regarding output escaping and SQL query practices. A concerning 100% of outputs are not properly escaped, which presents a high risk of Cross-Site Scripting (XSS) vulnerabilities. This means that any user-supplied data that is displayed by the plugin could potentially be injected with malicious scripts. While 60% of SQL queries use prepared statements, the remaining 40% do not, which could lead to SQL injection vulnerabilities if those queries handle user input unsafely. The complete absence of nonce checks, while perhaps justified by the limited unprotected entry points, is a general security weakness that could be exploited in conjunction with other issues. The lack of taint analysis data is also a minor concern as it prevents a deeper understanding of potential data flow vulnerabilities.
In conclusion, despite a clean vulnerability history and a small attack surface, the critical lack of output escaping and the presence of unescaped SQL queries represent substantial security risks. These issues outweigh the positive aspects and necessitate immediate attention.
Key Concerns
- No output escaping
- Unprepared SQL queries (40% of total)
- No nonce checks
Max Stats Table for WP Pro Quiz Security Vulnerabilities
Max Stats Table for WP Pro Quiz Code Analysis
SQL Query Safety
Output Escaping
Max Stats Table for WP Pro Quiz Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
Max Stats Table for WP Pro Quiz Maintenance & Trust
Maintenance Signals
Community Trust
Max Stats Table for WP Pro Quiz Alternatives
Soccer Widgets – Football Results & Rankings
webeki-soccer-scores
Soccer Widgets: use shortcodes to deliver updated soccer data like various table rankings and football results by competition.
Basketball Widgets – Basketball Results & Rankings
webeki-basketball-widgets-basketball-results-rankings
Basketball Widgets: use shortcodes to deliver updated basketball data like various table rankings and basketball results by competition.
TablePress – Tables in WordPress made easy
tablepress
Embed beautiful, accessible, and interactive tables into your WordPress website’s posts and pages, without having to write code!
Easy Table of Contents
easy-table-of-contents
Adds a user friendly and fully automatic way to create and display a table of contents generated from the page content.
GA Google Analytics – Connect Google Analytics to WordPress
ga-google-analytics
Adds Google Analytics tracking code to your WordPress site. Supports many tracking features.
Max Stats Table for WP Pro Quiz Developer Profile
1 plugin · 20 total installs
How We Detect Max Stats Table for WP Pro Quiz
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/max-stats-table-for-wp-pro-quiz/wppq-style.css/wp-content/plugins/max-stats-table-for-wp-pro-quiz/wppq-javascript.jswppq-javascript.jsmax-stats-table-for-wp-pro-quiz/wppq-style.css?ver=max-stats-table-for-wp-pro-quiz/wppq-javascript.js?ver=HTML / DOM Fingerprints
dbResetSuccessfulcenterTheThingsDivstatsLastCleareddbResetNoAdmindbResetErrordbResetReesedbResetSashawppqTestTitle+3 more EASTER EGG!onclick="return wppq_confirm_delete()"onclick="selectText('selectableTOO')"wppq_confirm_deleteselectText<div class='wppqTestTitle'><div class='wppqTestSubTitle'>Click anywhere in the text box below & the statistics will automatically be copied to your clipboard. Then you can paste the data into a spreadsheet. Use the spreadsheet's "text-to-column" function with a double-colon ( :: ) but no spaces for separator.<br /><br />These are the column headings:<br />Today's Date :: Site Name :: Quiz Name :: Number of Questions in Quiz :: Number of Quizzes Taken :: Number of Correct Answers :: Number of Incorrect Answers :: Percent Correct</div><pre class='outputBox' id='selectableTOO' onclick='selectText("selectableTOO")'><hr><hr><div class='wppqTestTitle'>Anonymous Test Results</div>