Plugin Pulse
← Pulse

Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker

by ExpressTech Systems · Uncategorized

Also makes 3 other plugins · 110.0K+ installs across the portfolio →

Quiz maker & survey maker for WordPress. Build quizzes, surveys, exams & assessments with scoring, results pages & lead capture — free & easy.

How scoring works →
90 Health · A
Maintenance 100/100
Rating quality 94/100
Support 70/100

90 health vs 56 average across 16,378 Uncategorized plugins

Directory ranking optimization

How it's scored →

How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.

99 / 100

Excellent listing optimization

Well tuned across the board

Update recency 100/100
WP compatibility 100/100
Rating quality 94/100
Listing tuning 100/100
Support resolution 100/100

Daily downloads

Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive

-22% vs prior 30d
600Downloads · Aug 26

30-day downloads

Rolling 30-day volume · peaks are release surges

44.0K

now · peak 72.9K

52.5K30d downloads · Aug 26

Directory rank vs rivals

wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you

Quiz and Survey Mast · #886 you Quiz Maker by AYS · #1224 HD Quiz · #2739 Quiz Maker, Poll Mak · #2863

Rating trend

Star average over time · dips mark rough releases

4.7Stars · Aug 26

Update activity

How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.

1.3Kper 1k installs · Aug 26

Release cadence

Actively maintained
from wp.org release tags

How often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.

18

releases in the last 12 months

1mo ago

latest release · v11.2.2

305

tagged releases on record

Recent releases

11.2.2 · 1mo ago11.2.1 · 1mo ago11.2.0 · 2mo ago11.1.5 · 2mo ago11.1.4 · 3mo ago11.1.3 · 3mo ago11.1.2 · 4mo ago11.1.1 · 4mo ago11.1.0 · 5mo ago11.0.0 · 5mo ago10.3.5 · 7mo ago10.3.4 · 8mo ago10.3.3 · 8mo ago10.3.2 · 9mo ago

What its installed base runs

via wordpress.org

Share of active installs on each version of this plugin · 40% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.

v11.2 40%
v11.1 15%
v10.3 8.2%
v10.2 7.8%
Older / other versions 30%

Estimated active installs

The public count shows “40K+”. Our estimate pins where the real number sits.

modeled estimate
40K–50K ≈47K

Modeled within the band wp.org reports; tightens as we track daily.

Install history · since 2015-03-10 · 1,489 observations

40KInstalls · Aug 26

Estimated value

What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.

Est. annual revenue

N/A

Est. acquisition value

N/A

No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. A declining trend compresses what a buyer would pay.

Details

Version
11.2.5
Last updated
yesterday
Added
2013-09-10 · 12 yrs old
Requires WP
5.0
Tested up to
7.0.4
Requires PHP
5.4

Recent reviews

All reviews on wp.org ↗
  1. Dino Pierini
    5mo ago

    Excelente herramienta para QUIZ

    Read on wp.org ↗
  2. OFILS.com
    5mo ago

    Keep up this great production mindset! It’s a quality I find rare. Currently, this open-source plugin is in my top 3 for WordPress.

    Read on wp.org ↗
  3. dock3r
    6mo ago

    This is the best Quiz plugin in WP repository. Its free plan is far better than most of other Quiz plugins paid version. The programming support is stellar. It has loads of hooks you can use from outside.

    Read on wp.org ↗
  4. erdeme61
    9mo ago

    Translations does not get picked up when you translate using loco and their provided .pot files. Poorly coded.

    Read on wp.org ↗
  5. btavagyok
    11mo ago

    The plugin is really reliable, does what it says on the label.However, we ran into some complications with the settings and started getting weird results from our tests.Asked for assistance from the support team and I can’t thank them enough for being so professional, fast and effective! They spotted our issues immediately and suggested ways to solve to problem. And my, are they patient 🙂Great product, wonderful team!Thanks for being there for us!

    Read on wp.org ↗
  6. lesponnes
    11mo ago

    Many thanks to QSM support team. They really took care of my request instantly. They proposed and implemented a very good solution to my quizz. Amazing support experience !

    Read on wp.org ↗
  7. etd87
    11mo ago

    I have used the paid plugin for 3 years now and I´m really happy with both plugin and support team!thanks!

    Read on wp.org ↗
  8. Tricia Belmonte
    12mo ago

    I am absolutely blown away by the support I received from the QSM team, especially Dhanush. I chose this plugin after a careful review of many options, and it led the way with its quiz options and professional appearance (and built-in email automation!). What I didn’t expect was to receive a level of care and expertise you’d expect from a premium service—and all on their free plugin! I ran into a complex issue where emails were not being sent after the quiz was completed. While I spent hours trying to troubleshoot it myself, the team took over that stress and took the time to identify and fix a deep database error on my site. They were polite, patient, and kept me informed through every step of the process. The plugin itself is fantastic, very easy to set up, and I can’t wait to add the upgraded options to make my fantastic quiz even more powerful. It’s their support, however, that truly makes this plugin stand out. I can’t wait to launch this amazing-looking quiz to the world and build my client’s leads list with it. This is definitely a five-star plugin. If you’re looking for a quiz plugin, look no further!

    Read on wp.org ↗

Latest updates

via wp.org changelog

Recent releases and news for this plugin

  1. Version 11.2.2 Security: Fixed a Contributor+ stored XSS in the Polar question type where the “required” setting was emitted into an unquoted HTML attribute (CVE-2026-14824). Credit: Meher Sudhakar Abbireddi. Security: Fixed a Contribu 11.2.2
  2. Version 11.2.1 Feature: Added an option to display the latest result in the Limited Entry Attempts feature. Bug: Fixed a JavaScript bug affecting the answer limit for Multiple Choice question types. Patch: Improved API request validati 11.2.1
  3. Version 11.2.0 Feature: Added the ability to configure page limits for individual pages when using manual pagination Bug: Resolved an issue where the progress bar was not displaying correctly for flashcard questions Patch: Fixed a stor 11.2.0
  4. Version 11.1.5 Feature: Added the %QSM_ADMIN_EMAIL% template variable to include the admin email in email templates Feature: Added %QSM_START_QUIZ_DATE% and %QSM_END_QUIZ_DATE% template variables to display the quiz start and end dates 11.1.5
  5. Version 11.1.4 Bug: Fixed issues with bulk question imports and file reset functionality Patch: Resolved an IDOR vulnerability in REST endpoints that could allow unauthorized quiz and question modifications Enhancement: Improved QSM Co 11.1.4
  6. Version 11.1.3 Bug: Resolved result display issues with random questions and answers Patch: Fixed a Cross-Site Scripting (XSS) vulnerability in rich answer type questions Enhancement: Improved the question hints UI in the new quiz rend 11.1.3

Known vulnerabilities

via Wordfence Intelligence

75 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.

  1. 2026-08-17 CVE-2026-14826 Authorization Bypass Through User-Controlled Key Affects <= 11.2.3 Patched in 11.2.4
  2. 2026-08-17 CVE-2026-14825 Authorization Bypass Through User-Controlled Key Affects <= 11.2.3 Patched in 11.2.4
  3. 2026-08-15 CVE-2026-15963 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 11.2.1 Patched in 11.2.2
  4. 2026-08-15 CVE-2026-11780 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 11.2.1 Patched in 11.2.2
  5. 2026-07-27 CVE-2026-14824 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 11.2.1 Patched in 11.2.2
  6. 2026-07-22 CVE-2026-65454 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 11.2.0 Patched in 11.2.1
  7. 2026-07-15 CVE-2026-13767 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 11.2.0 Patched in 11.2.1
  8. 2026-07-07 CVE-2026-14821 Missing Authorization Affects <= 11.1.4 Patched in 11.1.5
  9. 2026-07-06 CVE-2026-14820 Exposure of Sensitive Information to an Unauthorized Actor Affects < 11.1.3 Patched in 11.1.3
  10. 2026-07-02 CVE-2026-9230 Missing Authorization Affects <= 11.1.4 Patched in 11.1.5
  11. 2026-06-26 CVE-2026-9233 Missing Authorization Affects <= 11.1.4 Patched in 11.1.5
  12. 2026-06-05 CVE-2026-6448 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 11.1.2 Patched in 11.1.3
  13. 2026-06-03 CVE-2026-48867 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 11.1.2 Patched in 11.1.3
  14. 2026-04-23 CVE-2026-40787 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 11.0.0 Patched in 11.1.0
  15. 2026-04-16 CVE-2026-5797 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Affects <= 10.1.0 Patched in 11.1.1
  16. 2026-03-23 CVE-2026-2412 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 10.3.5 Patched in 11.0.0
  17. 2026-02-05 CVE-2026-25329 Missing Authorization Affects <= 10.3.4 Patched in 10.3.5
  18. 2026-02-01 CVE-2026-25324 Authorization Bypass Through User-Controlled Key Affects <= 10.3.4 Patched in 10.3.5
  19. 2026-01-28 CVE-2025-67987 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 10.3.1 Patched in 10.3.2
  20. 2026-01-08 CVE-2026-24358 Missing Authorization Affects <= 10.3.3 Patched in 10.3.4
  21. 2026-01-05 CVE-2025-9637 Missing Authorization Affects <= 10.3.1 Patched in 10.3.2
  22. 2026-01-05 CVE-2025-9318 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 10.3.1 Patched in 10.3.2
  23. 2026-01-05 CVE-2025-9294 Improper Authorization Affects <= 10.3.1 Patched in 10.3.2
  24. 2025-11-30 CVE-2025-63054 Missing Authorization Affects <= 10.3.2 Patched in 10.3.3
  25. 2025-09-03 CVE-2025-49401 Deserialization of Untrusted Data Affects <= 10.2.5 Patched in 10.2.6
  26. 2025-08-14 CVE-2025-55708 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 10.2.4 Patched in 10.2.5
  27. 2025-07-24 CVE-2025-6790 Cross-Site Request Forgery (CSRF) Affects <= 10.2.2 Patched in 10.2.3
  28. 2025-03-11 CVE-2024-10679 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 9.2.0 Patched in 9.2.1
  29. 2024-09-02 CVE-2024-8758 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 9.1.2 Patched in 9.1.3
  30. 2024-08-05 CVE-2024-6879 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 9.1.0 Patched in 9.1.1
  31. 2024-07-13 CVE-2024-6390 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 9.0.5 Patched in 9.1.0
  32. 2024-06-20 CVE-2024-6025 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 9.0.4 Patched in 9.0.5
  33. 2024-06-10 CVE-2024-4934 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 9.0.1 Patched in 9.0.2
  34. 2024-06-06 CVE-2024-3592 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 9.0.1 Patched in 9.0.2
  35. 2024-03-13 CVE-2024-27966 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 8.2.2 Patched in 8.2.3
  36. 2023-12-27 CVE-2023-51521 Cross-Site Request Forgery (CSRF) Affects <= 8.1.18 Patched in 8.1.19
  37. 2023-12-27 CVE-2023-51507 Missing Authorization Affects <= 8.1.16 Patched in 8.1.17
  38. 2023-11-16 CVE-2023-47834 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 8.1.13 Patched in 8.1.14
  39. 2023-09-12 Cross-Site Request Forgery (CSRF) Affects < 8.1.15 Patched in 8.1.16
  40. 2023-07-17 CVE-2023-3575 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 8.1.10 Patched in 8.1.11
  41. 2023-07-17 CVE-2023-37984 Improper Control of Interaction Frequency Affects <= 8.1.10 Patched in 8.1.11
  42. 2023-04-16 CVE-2023-28787 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 8.1.4 Patched in 8.1.5
  43. 2023-02-28 CVE-2023-26524 Cross-Site Request Forgery (CSRF) Affects <= 8.0.10 Patched in 8.1.0
  44. 2023-02-15 CVE-2023-0291 Missing Authorization Affects <= 8.0.8 Patched in 8.0.9
  45. 2023-02-08 CVE-2023-0292 Cross-Site Request Forgery (CSRF) Affects <= 8.0.8 Patched in 8.0.9
  46. 2022-12-16 CVE-2022-46862 Cross-Site Request Forgery (CSRF) Affects <= 8.0.7 Patched in 8.0.8
  47. 2022-11-29 CVE-2022-4032 Improper Input Validation Affects <= 8.0.4 Patched in 8.0.5
  48. 2022-11-16 CVE-2022-4033 Improper Input Validation Affects <= 8.0.4 Patched in 8.0.5
  49. 2022-10-23 Cross-Site Request Forgery (CSRF) Affects <= 7.3.10 Patched in 7.3.11
  50. 2022-10-21 CVE-2021-36898 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 7.3.4 Patched in 7.3.5
  51. 2022-10-21 CVE-2021-36906 Authorization Bypass Through User-Controlled Key Affects <= 7.3.6 Patched in 7.3.7
  52. 2022-10-21 CVE-2022-40698 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 7.3.10 Patched in 7.3.11
  53. 2022-10-21 CVE-2021-36864 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 7.3.4 Patched in 7.3.5
  54. 2022-10-21 CVE-2022-41652 Missing Authorization Affects <= 7.3.10 Patched in 7.3.11
  55. 2022-10-21 CVE-2021-36905 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 7.3.4 Patched in 7.3.5
  56. 2022-10-21 CVE-2021-36863 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 7.3.4 Patched in 7.3.5
  57. 2022-10-21 CVE-2022-42883 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 7.3.10 Patched in 7.3.11
  58. 2022-09-29 CVE-2021-36865 Authorization Bypass Through User-Controlled Key Affects <= 7.3.4 Patched in 7.3.5
  59. 2022-01-12 CVE-2022-0182 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 7.3.6 Patched in 7.3.7
  60. 2022-01-12 CVE-2022-0180 Cross-Site Request Forgery (CSRF) Affects <= 7.3.5 Patched in 7.3.7
  61. 2022-01-12 CVE-2022-0181 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 7.3.6 Patched in 7.3.7
  62. 2021-09-13 CVE-2021-24691 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 7.3.1 Patched in 7.3.2
  63. 2021-09-13 CVE-2021-20792 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 7.1.13 Patched in 7.1.14
  64. 2021-08-10 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 7.1.13 Patched in 7.1.14
  65. 2021-06-03 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 7.1.19 Patched in 7.1.19
  66. 2021-06-03 CVE-2021-24368 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 7.1.17 Patched in 7.1.18
  67. 2021-03-26 CVE-2021-24221 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 7.1.11 Patched in 7.1.12
  68. 2020-08-29 Unrestricted Upload of File with Dangerous Type Affects <= 7.0.1 Patched in 7.0.2
  69. 2020-08-03 CVE-2020-35951 Authorization Bypass Through User-Controlled Key Affects < 7.0.1 Patched in 7.0.1
  70. 2020-08-03 CVE-2020-35949 Unrestricted Upload of File with Dangerous Type Affects < 7.0.1 Patched in 7.0.1
  71. 2020-07-29 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 6.4.12 Patched in 7.0.0
  72. 2019-11-13 CVE-2019-17599 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 6.3.4 Patched in 6.3.5
  73. 2019-03-05 CVE-2019-9575 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 6.2.1 Patched in 6.2.2
  74. 2016-12-15 CVE-2016-11085 Cross-Site Request Forgery (CSRF) Affects < 4.7.9 Patched in 4.7.9
  75. 2015-07-16 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 4.4.4 Patched in 4.4.4

Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.

CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.

Behavioral tests

via WP Hive

Automated install-time checks, tested on PHP 8.1.12 · WP 7.0.1

Low memory footprint
Low page-speed impact
Runs on latest PHP + WP
No PHP errors
No JS errors
Activates cleanly
No resource errors
No external HTTP errors
Optimized database use
Frequently updated

Languages

via translate.wordpress.org

Translated into 43 languages, 1 at 90% or more

Persian 99%
Russian 55%
French (Canada) 53%
Ukrainian 41%
Swedish 40%
French (France) 35%
Spanish (Mexico) 31%
Romanian 26%
Dutch 23%
Italian 17%
Japanese 17%
Spanish (Spain) 16%
Chinese (China) 13%
Bosnian 11%
Esperanto 9%
Portuguese (Brazil) 8%
Danish 6%
Thai 6%
German 3%
Spanish (Argentina) 3%
English (Australia) 2%
English (Canada) 2%
English (UK) 2%
German (Formal) 2%

Plus 19 more locales with partial translations.

Growth timeline

Install-tier crossings we have observed, and how long each tier took to outgrow

No tier crossings observed yet.

Competes with

The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).

Compare head to head →

Embed this report card

Drop a live Pulse card for Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker into a readme, a review or a deck. It updates itself.

<iframe src="https://plugins.wpmayor.com/embed/quiz-master-next" width="480" height="300" style="border:0" loading="lazy" title="Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker — Plugin Pulse"></iframe>
Preview card ↗

Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker: 40K+ active installs, 4.7★ (1,280 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/quiz-master-next