Riddle Quiz Maker – easily add quizzes with unlimited lead generation to your site Security & Risk Analysis

wordpress.org/plugins/riddle-playful-content-on-the-go

Riddle’s beautifully intuitive quiz maker lets you create unlimited quizzes, personality tests, and more—no coding, no limits.

300 active installs v4.7.4 PHP 7.4+ WP 4.0+ Updated Dec 9, 2025
personality-test-makerpoll-makerquiz-makerriddlesurvey-maker
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Riddle Quiz Maker – easily add quizzes with unlimited lead generation to your site Safe to Use in 2026?

Generally Safe

Score 100/100

Riddle Quiz Maker – easily add quizzes with unlimited lead generation to your site has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The plugin "riddle-playful-content-on-the-go" v4.7.4 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices regarding SQL queries, utilizing prepared statements exclusively, and has no known historical vulnerabilities. The absence of a significant attack surface in terms of AJAX handlers, REST API routes, shortcodes, and cron events is also a positive indicator. However, the static analysis reveals critical concerns. The presence of the `unserialize` function, a known source of deserialization vulnerabilities, without any apparent sanitization or capability checks on its input is a major red flag. Furthermore, a very low percentage of output escaping (4%) suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities, as user-controlled data is likely being rendered directly in the browser without proper encoding.

The taint analysis showing zero unsanitized flows is encouraging but may not fully capture the risks associated with `unserialize` if its inputs are not strictly controlled. The vulnerability history being clean is a strength, implying a potentially well-maintained codebase. However, the absence of vulnerabilities thus far does not negate the immediate risks identified through static analysis. The combination of a dangerous function and poor output escaping presents a significant potential for exploitation, even without a history of public exploits.

Key Concerns

  • Dangerous function 'unserialize' used
  • Low output escaping percentage (4%)
  • No nonce checks detected
  • No capability checks detected
Vulnerabilities
None known

Riddle Quiz Maker – easily add quizzes with unlimited lead generation to your site Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Riddle Quiz Maker – easily add quizzes with unlimited lead generation to your site Code Analysis

Dangerous Functions
3
Raw SQL Queries
0
0 prepared
Unescaped Output
98
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Dangerous Functions Found

unserializeforeach (unserialize(RIDDLE_SHORTCODE_PARAMS) as $param) {src\Api\ShortcodeFilter.php:38
unserializeforeach (unserialize(RIDDLE_SHORTCODE_PARAMS) as $param) {src\classes\RiddleLoader.php:140
unserialize<?php foreach (unserialize(LEADERBOARD_MODES) as $value => $label): ?>src\views\leaderboard-creator\pages\creator-leaderboard.php:28

Output Escaping

4% escaped102 total outputs
Attack Surface

Riddle Quiz Maker – easily add quizzes with unlimited lead generation to your site Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

Riddle Quiz Maker – easily add quizzes with unlimited lead generation to your site Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 9, 2025
PHP min version7.4
Downloads51K

Community Trust

Rating92/100
Number of ratings9
Active installs300
Developer Profile

Riddle Quiz Maker – easily add quizzes with unlimited lead generation to your site Developer Profile

riddleinc

1 plugin · 300 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Riddle Quiz Maker – easily add quizzes with unlimited lead generation to your site

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/riddle-playful-content-on-the-go/public/css/bootstrap.css/wp-content/plugins/riddle-playful-content-on-the-go/public/css/plugin_v2.css/wp-content/plugins/riddle-playful-content-on-the-go/public/js/bootstrap.js/wp-content/plugins/riddle-playful-content-on-the-go/public/js/plugin.js
Script Paths
https://cdn.riddle.com/website/wp-plugin/js/riddle-gutenberg-block-v5.1.0.js
Version Parameters
riddle-playful-content-on-the-go/public/css/bootstrap.css?ver=riddle-playful-content-on-the-go/public/css/plugin_v2.css?ver=riddle-playful-content-on-the-go/public/js/bootstrap.js?ver=riddle-playful-content-on-the-go/public/js/plugin.js?ver=

HTML / DOM Fingerprints

CSS Classes
riddle-preview-container
Data Attributes
data-riddle-embed-id
JS Globals
Riddle
Shortcode Output
<div id='riddle-preview-container' data-riddle-embed-id=
FAQ

Frequently Asked Questions about Riddle Quiz Maker – easily add quizzes with unlimited lead generation to your site