Quantcast Choice Security & Risk Analysis

wordpress.org/plugins/quantcast-choice

The Quantcast Choice plugin implements the Quantcast Choice TCF v2.0 Consent Tool offering support for GDPR (including Non-IAB vendors), CCPA and ePri …

3K active installs v2.0.8 PHP + WP 4.0+ Updated Oct 6, 2022
ccpaeprivacyeprivacy-directivegdprgdpr-consent
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Quantcast Choice Safe to Use in 2026?

Generally Safe

Score 85/100

Quantcast Choice has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The quantcast-choice v2.0.8 plugin exhibits a very strong security posture based on the provided static analysis. The absence of any identified attack surface points, dangerous functions, file operations, external HTTP requests, or taint flows with unsanitized paths is highly commendable. The code also demonstrates good practices by using prepared statements for all SQL queries and a high percentage of properly escaped output. The lack of any recorded vulnerabilities in its history further reinforces this positive assessment, suggesting a well-maintained and secure codebase.

However, the complete absence of nonce checks and capability checks across all potential entry points, as indicated by the zero counts, presents a notable concern. While there are currently no identified entry points or vulnerabilities, this omission leaves a theoretical gap that could be exploited if an attack vector were to be discovered or introduced in future updates. The plugin's security relies heavily on its current lack of exposed attack surface rather than explicit authorization and integrity checks on its operations. In conclusion, the plugin is currently very secure due to a minimal attack surface and a clean vulnerability history, but the lack of authorization checks represents a potential weakness that should ideally be addressed.

Key Concerns

  • Missing nonce checks on potential entry points
  • Missing capability checks on potential entry points
Vulnerabilities
None known

Quantcast Choice Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Quantcast Choice Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
27 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

90% escaped30 total outputs
Attack Surface

Quantcast Choice Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 14
actionadmin_initadmin\class-qc-choice-admin-pages.php:57
actionadmin_menuadmin\class-qc-choice-admin-pages.php:58
actionadmin_noticesadmin\class-qc-choice-admin.php:66
actionplugins_loadedincludes\class-qc-choice.php:153
actionadmin_enqueue_scriptsincludes\class-qc-choice.php:169
filterscript_loader_tagincludes\class-qc-choice.php:184
actionwp_footerincludes\class-qc-choice.php:186
actionwp_enqueue_scriptsincludes\class-qc-choice.php:188
actionwp_enqueue_scriptsincludes\class-qc-choice.php:190
filterpage_attributes_dropdown_pages_argspublic\class-qc-choice-page.php:48
filtertheme_page_templatespublic\class-qc-choice-page.php:56
filterwp_insert_post_datapublic\class-qc-choice-page.php:63
filtertemplate_includepublic\class-qc-choice-page.php:71
actionplugins_loadedpublic\class-qc-choice-page.php:163
Maintenance & Trust

Quantcast Choice Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedOct 6, 2022
PHP min version
Downloads68K

Community Trust

Rating76/100
Number of ratings5
Active installs3K
Developer Profile

Quantcast Choice Developer Profile

Quantcast

2 plugins · 4K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Quantcast Choice

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/quantcast-choice/admin/css/style.min.css
Version Parameters
qc-choice/admin/css/style.min.css?ver=

HTML / DOM Fingerprints

CSS Classes
qc-choice-wrapper
HTML Comments
<!-- Quantcast Choice --><!-- Start Quantcast Choice--><!-- End Quantcast Choice--><!-- Quantcast Choice CMP -->+1 more
Data Attributes
data-qc-choice-cmp-utid
JS Globals
window.quantcastChoice
FAQ

Frequently Asked Questions about Quantcast Choice