
Quick Questionnaire Security & Risk Analysis
wordpress.org/plugins/quick-questionnaireCreate simple exercises directly in the editor.
Is Quick Questionnaire Safe to Use in 2026?
Generally Safe
Score 85/100Quick Questionnaire has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'quick-questionnaire' v2.5 exhibits a mixed security posture. On the positive side, the static analysis reveals no critical or high-severity issues in taint analysis, no dangerous functions used, and all SQL queries are properly prepared. The absence of known CVEs and a clean vulnerability history are also strong indicators of good security practices. However, there are significant concerns regarding output escaping and a lack of capability checks.
The primary weakness identified is that 100% of output is not properly escaped. This means that any data displayed by the plugin, if it originates from user input or other untrusted sources, could be vulnerable to Cross-Site Scripting (XSS) attacks. While the attack surface of AJAX handlers is protected by nonce checks, the absence of capability checks means that any authenticated user, regardless of their role or permissions, could potentially interact with these handlers, which could be a concern depending on the functionality. The plugin also has a moderate attack surface through its AJAX handlers, all of which are protected by nonce checks but lack permission checks.
Overall, the plugin has a solid foundation with secure SQL handling and no known historical vulnerabilities. However, the unescaped output presents a tangible risk of XSS. The lack of capability checks on AJAX handlers also introduces a potential for privilege escalation or unauthorized actions by authenticated users. Addressing the output escaping and implementing capability checks should be the priority to improve the plugin's security.
Key Concerns
- 0% output escaping
- No capability checks on AJAX handlers
Quick Questionnaire Security Vulnerabilities
Quick Questionnaire Code Analysis
SQL Query Safety
Output Escaping
Quick Questionnaire Attack Surface
AJAX Handlers 4
WordPress Hooks 7
Maintenance & Trust
Quick Questionnaire Maintenance & Trust
Maintenance Signals
Community Trust
Quick Questionnaire Alternatives
Plugin Check (PCP)
plugin-check
Plugin Check is a WordPress.org tool which provides checks to help plugins meet the directory requirements and follow various best practices.
Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More
reviews-feed
No API key required. Display Yelp and Google reviews for any business in a clean, customizable feed on your site.
Rich Showcase for Google Reviews
widget-google-reviews
Display up to 10 Google reviews in less than a minute. Continue collecting new reviews. No limits on connected places, widgets, shortcodes and blocks.
Strong Testimonials
strong-testimonials
An easy-to-use testimonial plugin to collect and show customer feedback in WordPress
Site Reviews
site-reviews
Site Reviews is a complete review management solution that integrates with WooCommerce and SureCart and works similarly to reviews on Amazon, Tripadvi …
Quick Questionnaire Developer Profile
4 plugins · 1K total installs
How We Detect Quick Questionnaire
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/quick-questionnaire/css/qq.css/wp-content/plugins/quick-questionnaire/js/qq.js/wp-content/plugins/quick-questionnaire/js/qq.jsquick-questionnaire/js/qq.js?ver=1.0.0HTML / DOM Fingerprints
window.qq_my_post_typewindow.qq_all_postsQQ_POST_IDQQ_ANSWERSQQ_SHOW_BUTTONmy_ajax_obj