
Watu Quiz Security & Risk Analysis
wordpress.org/plugins/watuCreates exams, surveys, and quizzes with unlimited number of questions and answers. Mobile/touch - friendly.
Is Watu Quiz Safe to Use in 2026?
Generally Safe
Score 88/100Watu Quiz has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "watu" plugin v3.4.6 presents a mixed security posture. While it demonstrates good practices in SQL query handling and includes a substantial number of nonce and capability checks, several concerning aspects warrant attention. The static analysis reveals a significant attack surface, with 5 out of 11 entry points lacking authentication checks. This is further compounded by the presence of four 'unserialize' calls, a known dangerous function, and taint analysis indicating two high-severity flows with unsanitized paths. The plugin's vulnerability history is also a significant concern, with 17 known CVEs, including 4 high-severity ones, and common vulnerability types such as missing authorization and cross-site scripting. The fact that the last reported vulnerability was in late 2025 (though this seems like a typo and likely refers to a past date) might suggest recent updates, but the historical pattern of multiple vulnerabilities, particularly those related to authorization and input sanitization, points to a recurring need for stringent security development and auditing processes.
Key Concerns
- Unprotected AJAX handlers
- High severity taint flows
- Dangerous unserialize function usage
- High number of high severity historical CVEs
- Outputs with partial proper escaping
- Common vulnerability types: Missing Auth & XSS
Watu Quiz Security Vulnerabilities
CVEs by Year
Severity Breakdown
17 total CVEs
Watu Quiz <= 3.4.5 - Missing Authorization
Watu Quiz <= 3.4.5 - Missing Authorization
Watu Quiz <= 3.4.4 - Unauthenticated Stored Cross-Site Scripting via HTTP Referer
Watu Quiz <= 3.4.3 - Authenticated (Administrator+) SQL Injection
Watu Quiz <= 3.4.2 - Reflected Cross-Site Scripting
Watu Quiz <= 3.4.1.2 - Authenticated (Contributor+) SQL Injection
Watu Quiz <= 3.4.1.1 - Authenticated (Author+) Stored Cross-Site Scripting
Watu Quiz <= 3.4.1 - Sensitive Information Disclosure
Watu Quiz <= 3.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Watu Quiz <= 3.3.9.2 - Reflected Cross-Site Scripting via 'question'
Watu Quiz <= 3.3.9 - Reflected Cross-Site Scripting
Watu Quiz <= 3.3.8 - Authenticated (Admin+) Stored Cross-Site Scripting
Watu Quiz <= 3.3.8.1 - Reflected Cross-Site Scripting
Watu Quiz <= 3.3.8.2 - Authenticated (Admin+) Stored Cross-Site Scripting
Watu Quiz 3.1.2.1 - 3.1.2.5 - Reflected Cross-Site Scripting
Watu Quiz <= 2.6.7 - Authenticated (Admin+) SQL Injection
Watu Quiz <= 2.5.0.1 - Stored Cross-Site Scripting
Watu Quiz Release Timeline
Watu Quiz Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Watu Quiz Attack Surface
AJAX Handlers 5
Shortcodes 6
WordPress Hooks 16
Maintenance & Trust
Watu Quiz Maintenance & Trust
Maintenance Signals
Community Trust
Watu Quiz Alternatives
WpCues Basic Quiz
wpcues-basic-quiz
Create math / html / multimedia rich quiz. Award Mozilla Open Badges, Create colorful charts / leader boards and sell your quizzes using stripe.
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker
quiz-master-next
Create quizzes, surveys, and tests easily on WordPress with this versatile plugin. Perfect for engaging any audience and gathering valuable insights!
Chained Quiz
chained-quiz
Create a quiz where the next question depends on the answer to the previous question. Final quiz results depend on the amount of collected points.
Quiz Creator – Easy Quiz, Survey & Test Maker
quiz-creator
Create and manage interactive quizzes with multiple question types, automatic scoring, timed quizzes, and email notifications.
Watu to MailChimp
watu-bridge-to-mailchimp
A bridge between the Watu Quiz plugin and MailChimp /*** This program is free software: you can redistribute it and/or modify it under the terms of …
Watu Quiz Developer Profile
10 plugins · 5K total installs
How We Detect Watu Quiz
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/watu/css/exam-list.css/wp-content/plugins/watu/css/jquery-ui.css/wp-content/plugins/watu/css/style.css/wp-content/plugins/watu/js/watu.js/wp-content/plugins/watu/js/jquery-ui.js/wp-content/plugins/watu/js/raphael-min.js/wp-content/plugins/watu/js/chart.js/wp-content/plugins/watu/js/social-sharing.js+4 more/wp-content/plugins/watu/js/watu.js/wp-content/plugins/watu/js/jquery-ui.js/wp-content/plugins/watu/js/raphael-min.js/wp-content/plugins/watu/js/chart.js/wp-content/plugins/watu/js/social-sharing.js/wp-content/plugins/watu/js/watu-admin.js+3 more/wp-content/plugins/watu/css/exam-list.css?ver=/wp-content/plugins/watu/css/jquery-ui.css?ver=/wp-content/plugins/watu/css/style.css?ver=/wp-content/plugins/watu/js/watu.js?ver=/wp-content/plugins/watu/js/jquery-ui.js?ver=/wp-content/plugins/watu/js/raphael-min.js?ver=/wp-content/plugins/watu/js/chart.js?ver=/wp-content/plugins/watu/js/social-sharing.js?ver=/wp-content/plugins/watu/js/watu-admin.js?ver=/wp-content/plugins/watu/js/exam-options.js?ver=/wp-content/plugins/watu/js/watu-import.js?ver=/wp-content/plugins/watu/js/watu-quiz-editor.js?ver=HTML / DOM Fingerprints
watu-quiz-listwatu-exam-questionswatu-quiz-resultswatu-quiz-formwatu-question-itemwatu-answer-itemwatu-progress-barwatu-chart-container+4 more<!-- Watu Quiz --><!-- Watu Question --><!-- Watu Answer --><!-- Watu Results -->+1 moredata-exam-iddata-question-iddata-quiz-worddata-quiz-word-pluraldata-watu-noncewatu_ajax_urlwatu_quiz_idwatu_exam_datawatu_quiz_settingswatu_user_progress/wp-json/watu/v1/submit-quiz/wp-json/watu/v1/get-quiz-data/wp-json/watu/v1/save-progress[WATU][watu][watushare-buttons][watu-basic-chart]