
Random Quiz Generator for LifterLMS Security & Risk Analysis
wordpress.org/plugins/random-quiz-addon-for-lifterlmsRandomize your quizzes and automatically generate a random question set for each attempt in LifterLMS.
Is Random Quiz Generator for LifterLMS Safe to Use in 2026?
Generally Safe
Score 92/100Random Quiz Generator for LifterLMS has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'random-quiz-addon-for-lifterlms' v1.0.2 exhibits a concerning security posture due to significant gaps in authentication and output sanitization. While the absence of dangerous functions, SQL injection vulnerabilities through prepared statements, file operations, and external HTTP requests is a positive sign, these strengths are overshadowed by critical weaknesses.
The most alarming findings are the two unprotected AJAX handlers, which represent direct entry points into the plugin without any form of authentication or authorization checks. This is further compounded by a complete lack of output escaping across all identified output points, making it highly susceptible to Cross-Site Scripting (XSS) attacks. The static analysis also revealed no nonce checks or capability checks, reinforcing the lack of security for these AJAX endpoints.
The plugin's vulnerability history is clean, with no recorded CVEs. This might indicate a generally well-maintained codebase or a lack of past significant security findings. However, the current code analysis strongly suggests that the plugin is ripe for exploitation due to the identified security flaws. The conclusion is that while the plugin doesn't suffer from known historical vulnerabilities, its current implementation presents immediate and severe risks that require urgent attention.
Key Concerns
- AJAX handlers without authentication
- No output escaping
- No nonce checks
- No capability checks
Random Quiz Generator for LifterLMS Security Vulnerabilities
Random Quiz Generator for LifterLMS Code Analysis
Output Escaping
Random Quiz Generator for LifterLMS Attack Surface
AJAX Handlers 2
WordPress Hooks 7
Maintenance & Trust
Random Quiz Generator for LifterLMS Maintenance & Trust
Maintenance Signals
Community Trust
Random Quiz Generator for LifterLMS Alternatives
Custom Template for LifterLMS
custom-template-lifterlms
The selected custom template will replace default LifterLMS course template for non-enrolled students.
Experience API for LifterLMS by Grassblade
grassblade-xapi-lifterlms
This plugin enables the Experience API (xAPI / Tin Can) , SCORM 1.2 and SCORM 2004 support on the LifterLMS by integrating with GrassBlade xAPI Compan …
Learning Management System (LMS) Chat Application
lms-chat
WP LMS Conversation allow to conversation with LMS teacher or other student.
Liftor
liftor
It'll enable the theme builder of Elementor for lesson post types.
CopeCart-LifterLMS
copecart-lifterlmsg
CopeCart-LifterLMSG
Random Quiz Generator for LifterLMS Developer Profile
21 plugins · 40K total installs
How We Detect Random Quiz Generator for LifterLMS
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/random-quiz-addon-for-lifterlms/js/admin.js/wp-content/plugins/random-quiz-addon-for-lifterlms/js/frontend.jsjs/admin.jsjs/frontend.jsrandom-quiz-addon-for-lifterlms/js/admin.js?ver=random-quiz-addon-for-lifterlms/js/frontend.js?ver=HTML / DOM Fingerprints
ags-llrq-quiz-lengthlifterlms\templates\course\complete-lesson-link.phpags_llrq_random_subsetags_llrq_random_subset_countags_llrq_random_subset_userags_llrq_random_subset_user_defaultags_llrq_quiz_length