
Quizy Security & Risk Analysis
wordpress.org/plugins/quizyQuizy enables you to create quizzes, tests with several common settings with evaluation
Is Quizy Safe to Use in 2026?
Generally Safe
Score 85/100Quizy has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The Quizy plugin version 1.1 exhibits a generally positive security posture, with no recorded vulnerabilities or CVEs. The plugin demonstrates good practices in its use of prepared statements for SQL queries and includes both nonce and capability checks for its single entry point (a shortcode). This indicates a proactive approach to preventing common WordPress exploits.
However, the static analysis does reveal areas for improvement. The presence of the `unserialize` function is a significant concern, as it can be a vector for object injection vulnerabilities if not handled with extreme care and strict validation of the serialized data. Furthermore, the output escaping is only 33% proper, which poses a risk of cross-site scripting (XSS) vulnerabilities if user-supplied data is not adequately sanitized before being displayed.
While the lack of historical vulnerabilities is encouraging, it doesn't negate the risks identified in the code. The taint analysis, although showing no critical or high severity unsanitized flows, did identify one flow with an unsanitized path, which warrants further investigation and mitigation. Overall, Quizy 1.1 has a solid foundation but requires attention to the `unserialize` function and output escaping to achieve a more robust security profile.
Key Concerns
- Dangerous function unserialize found
- Low percentage of properly escaped output
- Taint flow with unsanitized path
Quizy Security Vulnerabilities
Quizy Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Quizy Attack Surface
Shortcodes 1
WordPress Hooks 21
Maintenance & Trust
Quizy Maintenance & Trust
Maintenance Signals
Community Trust
Quizy Alternatives
Calculate Values with Shortcodes
calculate-values-with-shortcodes
Allows you to display calculated values in your posts and pages. You can even use dynamic shortcodes as variables!
WP Shortcodes Plugin — Shortcodes Ultimate
shortcodes-ultimate
A comprehensive collection of visual components for your site
MW WP Form
mw-wp-form
MW WP Form is shortcode base contact form plugin. This plugin have many features. For example you can use many validation rules, inquiry data saving, …
Shortcoder — Create Shortcodes for Anything
shortcoder
Create custom "Shortcodes" easily for HTML, JavaScript, CSS code snippets and use the shortcodes within posts, pages & widgets
Display Posts – Easy lists, grids, navigation, and more
display-posts-shortcode
Add a listing of content on your website using a simple shortcode. Filter the results by category, author, and more.
Quizy Developer Profile
4 plugins · 1K total installs
How We Detect Quizy
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/quizy/admin/assets/list-questions.js/wp-content/plugins/quizy/admin/assets/admin.js/wp-content/plugins/quizy/admin/assets/style.css/wp-content/plugins/quizy/assets/style.css/wp-content/plugins/quizy/assets/quizy.js/wp-content/plugins/quizy/admin/assets/list-questions.js/wp-content/plugins/quizy/admin/assets/admin.js/wp-content/plugins/quizy/assets/quizy.jsHTML / DOM Fingerprints
quizy-wrapquizy-main-content<!-- Quizy settings page --><!-- Quizy Options --><!-- Quizy - Main Wrapper --><!-- Quizy Admin Script -->+1 moredata-quizy-iddata-quizy-ajax-urldata-quizy-nonceQuizyAdminQuizyFrontend<div class="quizy-shortcode-wrapper"><div class="quizy-quiz-container">