
WPLMS User Generated Quiz Security & Risk Analysis
wordpress.org/plugins/wplms-user-generated-quizAdds shortcode for mock quiz which user selects tags and creates quiz for himself .
Is WPLMS User Generated Quiz Safe to Use in 2026?
Generally Safe
Score 85/100WPLMS User Generated Quiz has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wplms-user-generated-quiz" v1.1 plugin exhibits a mixed security posture. While it demonstrates good practices by not utilizing dangerous functions, performing all SQL queries with prepared statements, and avoiding file operations and external HTTP requests, there are significant areas of concern. The complete lack of output escaping is a critical weakness, exposing the plugin to potential Cross-Site Scripting (XSS) vulnerabilities. Additionally, the absence of capability checks on its entry points, despite the presence of a nonce check on one AJAX handler, suggests a lack of robust authorization, which could be exploited if an attacker can bypass or manipulate the nonce. The plugin's vulnerability history is clean, with no recorded CVEs, which is positive. However, this could also indicate a lack of historical scrutiny rather than inherent perfect security. In conclusion, while the plugin avoids common pitfalls like raw SQL and dangerous functions, the critical issue of unescaped output and the potential for authorization bypass create a notable risk that needs to be addressed.
Key Concerns
- No output escaping
- No capability checks on entry points
WPLMS User Generated Quiz Security Vulnerabilities
WPLMS User Generated Quiz Code Analysis
Output Escaping
WPLMS User Generated Quiz Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
WPLMS User Generated Quiz Maintenance & Trust
Maintenance Signals
Community Trust
WPLMS User Generated Quiz Alternatives
LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes
lifterlms
Complete e-learning platform to sell online courses, protect lessons, offer memberships, and quiz students. WP Learning Management System.
LifterLMS Labs
lifterlms-labs
A collection of experimental, conceptual, and possibly silly features which improve and enhance the functionality of the LifterLMS core.
WPLMS H5P
wplms-h5p-plugin
Integrates H5P with WPLMS.
Wplms bigbluebutton addon
bbb-wplms
Wplms bigbluebutton addon is a social login integration plugin for BuddyPress.
myCred Tutor LMS – Gamification in eLearning
mycred-tutor-lms-gamification-in-elearning
Connect mycred with Tutor LMS
WPLMS User Generated Quiz Developer Profile
6 plugins · 140 total installs
How We Detect WPLMS User Generated Quiz
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wplms-user-generated-quiz/css/wplms-umq-admin.css/wp-content/plugins/wplms-user-generated-quiz/css/wplms-umq-frontend.css/wp-content/plugins/wplms-user-generated-quiz/js/wplms-umq-admin.js/wp-content/plugins/wplms-user-generated-quiz/js/wplms-umq-frontend.js/wp-content/plugins/wplms-user-generated-quiz/js/wplms-umq-frontend.js/wp-content/plugins/wplms-user-generated-quiz/css/wplms-umq-admin.css?ver=/wp-content/plugins/wplms-user-generated-quiz/css/wplms-umq-frontend.css?ver=/wp-content/plugins/wplms-user-generated-quiz/js/wplms-umq-admin.js?ver=/wp-content/plugins/wplms-user-generated-quiz/js/wplms-umq-frontend.js?ver=HTML / DOM Fingerprints
user_quiz_formquiz_tags_field_wrapperquiz_tagquestion_numberquiz_marksadd_more_question_tagremove_quiz_tagall_quiz_tags_feilds+4 moredata-quiz_idWPLMS_UMQ_AJAX[user_dynamic_quiz]