
OnionBuzz Security & Risk Analysis
wordpress.org/plugins/onionbuzz-viral-quizCreate BuzzFeed like quizzes on your WordPress website or blog.
Is OnionBuzz Safe to Use in 2026?
High Risk
Score 47/100OnionBuzz carries significant security risk with 3 known CVEs, 1 still unpatched. Consider switching to a maintained alternative.
The "onionbuzz-viral-quiz" plugin exhibits a concerning security posture, primarily due to a vast attack surface with no authentication checks on any of its entry points. All 29 AJAX handlers are unprotected, creating a significant risk for unauthorized actions. This is further exacerbated by the fact that 100% of analyzed taint flows have unsanitized paths, although no critical or high severity issues were found in this specific analysis. The plugin's vulnerability history is a major red flag, with three known CVEs, including two critical and one medium, and importantly, one critical vulnerability remains unpatched. This historical pattern of critical SQL injection and CSRF vulnerabilities, coupled with the current lack of proper sanitization and authentication, suggests a recurring inability to address severe security flaws. While the plugin doesn't appear to use dangerous functions or perform file operations, the absence of nonce and capability checks, combined with a low percentage of properly escaped output, points to several potential weaknesses that could be exploited.
Key Concerns
- 29 AJAX handlers without auth checks
- 17 flows with unsanitized paths
- 0 Nonce checks
- 0 Capability checks
- 1 unpatched critical CVE
- 2 critical CVEs in history
- 16% properly escaped output
- Bundled outdated jQuery v3.1.1
OnionBuzz Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
OnionBuzz <= 1.0.7 - Cross-Site Request Forgery
OnionBuzz Plugin < 1.2.7 - SQL Injection
Viral Quiz Maker - OnionBuzz < 1.2.2 - SQL Injection
OnionBuzz Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
OnionBuzz Attack Surface
AJAX Handlers 29
WordPress Hooks 17
Maintenance & Trust
OnionBuzz Maintenance & Trust
Maintenance Signals
Community Trust
OnionBuzz Alternatives
ARI Stream Quiz – WordPress Quizzes Builder
ari-stream-quiz
Easy to use WordPress Viral Quiz Plugin. Create Trivia and Personality quizzes in BuzzFeed style and collect unlimited leads.
Quiz Cat – WordPress Quiz Plugin
quiz-cat
Quiz Cat Lets You Create Beautiful Viral BuzzFeed-style Quizzes That Drive Social Shares & User Engagement. Set It Up In 2 Minutes.
Shortcake Bakery
shortcake-bakery
A fine selection of Shortcake-powered shortcodes.
WP Quizr
wp-quizr
Create Buzzfeed-style quizzes and share results on social media.
WP Capitalized Titles
capitalized-wp-titles
WP Capitalized Titles by http://www.easyguidetowp.com/
OnionBuzz Developer Profile
3 plugins · 230 total installs
How We Detect OnionBuzz
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/onionbuzz-viral-quiz/vendors/pnotify/pnotify.min.js/wp-content/plugins/onionbuzz-viral-quiz/vendors/sharer/sharer.js/wp-content/plugins/onionbuzz-viral-quiz/frontend/js/frontend.js/wp-content/plugins/onionbuzz-viral-quiz/frontend/css/frontend.css/wp-content/plugins/onionbuzz-viral-quiz/vendors/animations/animations.cssvendors/pnotify/pnotify.min.jsvendors/sharer/sharer.jsfrontend/js/frontend.jsfrontend/css/frontend.cssvendors/animations/animations.cssonionbuzz-viral-quiz/vendors/pnotify/pnotify.min.js?ver=onionbuzz-viral-quiz/vendors/sharer/sharer.js?ver=onionbuzz-viral-quiz/frontend/js/frontend.js?ver=onionbuzz-viral-quiz/frontend/css/frontend.css?ver=onionbuzz-viral-quiz/vendors/animations/animations.css?ver=HTML / DOM Fingerprints
<!-- Onionbuzz Custom CSS --><!-- Onionbuzz Custom CSS END -->data-obvqonionbuzz_paramsonionbuzz_lng/wp-json/onionbuzz-viral-quiz/v1/getquiz/wp-json/onionbuzz-viral-quiz/v1/getquizdata[onionbuzz_quiz[quiz_display