Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker
by ExpressTech Systems · Uncategorized
Also makes 3 other plugins · 110.0K+ installs across the portfolio →
Quiz maker & survey maker for WordPress. Build quizzes, surveys, exams & assessments with scoring, results pages & lead capture — free & easy.
90 health vs 56 average across 16,378 Uncategorized plugins
Directory ranking optimization
How it's scored →How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.
Excellent listing optimization
Well tuned across the board
Daily downloads
Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive
30-day downloads
Rolling 30-day volume · peaks are release surges
44.0K
now · peak 72.9K
Directory rank vs rivals
wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you
Rating trend
Star average over time · dips mark rough releases
Update activity
How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.
Release cadence
Actively maintainedHow often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.
18
releases in the last 12 months
1mo ago
latest release · v11.2.2
305
tagged releases on record
Recent releases
What its installed base runs
via wordpress.orgShare of active installs on each version of this plugin · 40% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.
Estimated active installs
The public count shows “40K+”. Our estimate pins where the real number sits.
Modeled within the band wp.org reports; tightens as we track daily.
Install history · since 2015-03-10 · 1,489 observations
Estimated value
What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.
Est. annual revenue
Est. acquisition value
No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. A declining trend compresses what a buyer would pay.
Details
Recent reviews
All reviews on wp.org ↗- ★★★★★ Dino Pierini5mo ago
Excelente herramienta para QUIZ
Read on wp.org ↗ - ★★★★★ OFILS.com5mo ago
Keep up this great production mindset! It’s a quality I find rare. Currently, this open-source plugin is in my top 3 for WordPress.
Read on wp.org ↗ - ★★★★★ dock3r6mo ago
This is the best Quiz plugin in WP repository. Its free plan is far better than most of other Quiz plugins paid version. The programming support is stellar. It has loads of hooks you can use from outside.
Read on wp.org ↗ - ★★★★★ erdeme619mo ago
Translations does not get picked up when you translate using loco and their provided .pot files. Poorly coded.
Read on wp.org ↗ - ★★★★★ btavagyok11mo ago
The plugin is really reliable, does what it says on the label.However, we ran into some complications with the settings and started getting weird results from our tests.Asked for assistance from the support team and I can’t thank them enough for being so professional, fast and effective! They spotted our issues immediately and suggested ways to solve to problem. And my, are they patient 🙂Great product, wonderful team!Thanks for being there for us!
Read on wp.org ↗ - ★★★★★ lesponnes11mo ago
Many thanks to QSM support team. They really took care of my request instantly. They proposed and implemented a very good solution to my quizz. Amazing support experience !
Read on wp.org ↗ - ★★★★★ etd8711mo ago
I have used the paid plugin for 3 years now and I´m really happy with both plugin and support team!thanks!
Read on wp.org ↗ - ★★★★★ Tricia Belmonte12mo ago
I am absolutely blown away by the support I received from the QSM team, especially Dhanush. I chose this plugin after a careful review of many options, and it led the way with its quiz options and professional appearance (and built-in email automation!). What I didn’t expect was to receive a level of care and expertise you’d expect from a premium service—and all on their free plugin! I ran into a complex issue where emails were not being sent after the quiz was completed. While I spent hours trying to troubleshoot it myself, the team took over that stress and took the time to identify and fix a deep database error on my site. They were polite, patient, and kept me informed through every step of the process. The plugin itself is fantastic, very easy to set up, and I can’t wait to add the upgraded options to make my fantastic quiz even more powerful. It’s their support, however, that truly makes this plugin stand out. I can’t wait to launch this amazing-looking quiz to the world and build my client’s leads list with it. This is definitely a five-star plugin. If you’re looking for a quiz plugin, look no further!
Read on wp.org ↗
Latest updates
via wp.org changelogRecent releases and news for this plugin
- — Version 11.2.2 Security: Fixed a Contributor+ stored XSS in the Polar question type where the “required” setting was emitted into an unquoted HTML attribute (CVE-2026-14824). Credit: Meher Sudhakar Abbireddi. Security: Fixed a Contribu 11.2.2
- — Version 11.2.1 Feature: Added an option to display the latest result in the Limited Entry Attempts feature. Bug: Fixed a JavaScript bug affecting the answer limit for Multiple Choice question types. Patch: Improved API request validati 11.2.1
- — Version 11.2.0 Feature: Added the ability to configure page limits for individual pages when using manual pagination Bug: Resolved an issue where the progress bar was not displaying correctly for flashcard questions Patch: Fixed a stor 11.2.0
- — Version 11.1.5 Feature: Added the %QSM_ADMIN_EMAIL% template variable to include the admin email in email templates Feature: Added %QSM_START_QUIZ_DATE% and %QSM_END_QUIZ_DATE% template variables to display the quiz start and end dates 11.1.5
- — Version 11.1.4 Bug: Fixed issues with bulk question imports and file reset functionality Patch: Resolved an IDOR vulnerability in REST endpoints that could allow unauthorized quiz and question modifications Enhancement: Improved QSM Co 11.1.4
- — Version 11.1.3 Bug: Resolved result display issues with random questions and answers Patch: Fixed a Cross-Site Scripting (XSS) vulnerability in rich answer type questions Enhancement: Improved the question hints UI in the new quiz rend 11.1.3
Known vulnerabilities
via Wordfence Intelligence75 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.
- Medium · 4.3 Quiz And Survey Master <= 11.2.3 - Authenticated (Contributor+) Insecure Direct Object Reference ↗2026-08-17 CVE-2026-14826 Authorization Bypass Through User-Controlled Key Affects <= 11.2.3 Patched in 11.2.4
- Medium · 4.3 Quiz And Survey Master <= 11.2.3 - Authenticated (Contributor+) Insecure Direct Object Reference ↗2026-08-17 CVE-2026-14825 Authorization Bypass Through User-Controlled Key Affects <= 11.2.3 Patched in 11.2.4
- 2026-08-15 CVE-2026-15963 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 11.2.1 Patched in 11.2.2
- 2026-08-15 CVE-2026-11780 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 11.2.1 Patched in 11.2.2
- Medium · 6.4 Quiz And Survey Master <= 11.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting ↗2026-07-27 CVE-2026-14824 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 11.2.1 Patched in 11.2.2
- Medium · 6.5 Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker <= 11.2.0 - Authenticated (Contributor+) SQL Injection ↗2026-07-22 CVE-2026-65454 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 11.2.0 Patched in 11.2.1
- Medium · 6.5 Quiz and Survey Master (QSM) <= 11.2.0 - Authenticated (Custom+) SQL Injection via 'pages' Parameter ↗2026-07-15 CVE-2026-13767 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 11.2.0 Patched in 11.2.1
- Medium · 5.3 Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker < 11.1.3 - Unauthenticated User Enumeration ↗2026-07-06 CVE-2026-14820 Exposure of Sensitive Information to an Unauthorized Actor Affects < 11.1.3 Patched in 11.1.3
- Medium · 4.9 Quiz and Survey Master (QSM) <= 11.1.2 - Authenticated (Admin+) SQL Injection via 'order' and 'limit' Parameters ↗2026-06-05 CVE-2026-6448 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 11.1.2 Patched in 11.1.3
- 2026-06-03 CVE-2026-48867 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 11.1.2 Patched in 11.1.3
- 2026-04-23 CVE-2026-40787 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 11.0.0 Patched in 11.1.0
- 2026-04-16 CVE-2026-5797 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Affects <= 10.1.0 Patched in 11.1.1
- Medium · 6.5 Quiz and Survey Master (QSM) <= 10.3.5 - Authenticated (Contributor+) SQL Injection via 'merged_question' Parameter ↗2026-03-23 CVE-2026-2412 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 10.3.5 Patched in 11.0.0
- 2026-02-01 CVE-2026-25324 Authorization Bypass Through User-Controlled Key Affects <= 10.3.4 Patched in 10.3.5
- 2026-01-28 CVE-2025-67987 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 10.3.1 Patched in 10.3.2
- Medium · 6.5 Quiz and Survey Master (QSM) <= 10.3.1 - Authenticated (Subscriber+) SQL Injection via `is_linking` Query Parameter ↗2026-01-05 CVE-2025-9318 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 10.3.1 Patched in 10.3.2
- 2025-08-14 CVE-2025-55708 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 10.2.4 Patched in 10.2.5
- Medium · 4.4 Quiz and Survey Master (QSM) <= 9.2.0 - Authenticated (Admin+) Stored Cross-Site Scripting ↗2025-03-11 CVE-2024-10679 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 9.2.0 Patched in 9.2.1
- Medium · 4.4 Quiz and Survey Master (QSM) <= 9.1.2 - Authenticated (Admin+) Stored Cross-Site Scripting ↗2024-09-02 CVE-2024-8758 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 9.1.2 Patched in 9.1.3
- Medium · 6.4 Quiz and Survey Master (QSM) <= 9.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting ↗2024-08-05 CVE-2024-6879 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 9.1.0 Patched in 9.1.1
- Medium · 6.4 Quiz and Survey Master <= 9.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting ↗2024-07-13 CVE-2024-6390 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 9.0.5 Patched in 9.1.0
- Medium · 6.4 Quiz and Survey Master <= 9.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting ↗2024-06-20 CVE-2024-6025 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 9.0.4 Patched in 9.0.5
- 2024-06-10 CVE-2024-4934 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 9.0.1 Patched in 9.0.2
- Critical · 9.9 Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress <= 9.0.1 - Authenticated (Contributor+) SQL Injection ↗2024-06-06 CVE-2024-3592 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 9.0.1 Patched in 9.0.2
- Medium · 4.4 Quiz And Survey Master <= 8.2.2 - Authenticated (Administrator+) Stored Cross-Site Scripting ↗2024-03-13 CVE-2024-27966 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 8.2.2 Patched in 8.2.3
- Medium · 6.4 Quiz And Survey Master <= 8.1.13 - Authenticated (Contributor+) Stored Cross-Site Scripting ↗2023-11-16 CVE-2023-47834 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 8.1.13 Patched in 8.1.14
- 2023-09-12 Cross-Site Request Forgery (CSRF) Affects < 8.1.15 Patched in 8.1.16
- Medium · 6.4 Quiz And Survey Master <= 8.1.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via Question Title ↗2023-07-17 CVE-2023-3575 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 8.1.10 Patched in 8.1.11
- 2023-07-17 CVE-2023-37984 Improper Control of Interaction Frequency Affects <= 8.1.10 Patched in 8.1.11
- 2023-04-16 CVE-2023-28787 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 8.1.4 Patched in 8.1.5
- 2022-10-23 Cross-Site Request Forgery (CSRF) Affects <= 7.3.10 Patched in 7.3.11
- 2022-10-21 CVE-2021-36898 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 7.3.4 Patched in 7.3.5
- 2022-10-21 CVE-2021-36906 Authorization Bypass Through User-Controlled Key Affects <= 7.3.6 Patched in 7.3.7
- 2022-10-21 CVE-2022-40698 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 7.3.10 Patched in 7.3.11
- 2022-10-21 CVE-2021-36864 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 7.3.4 Patched in 7.3.5
- Medium · 6.4 Quiz And Survey Master <= 7.3.4 - Multiple Authenticated (Contributor+) Stored Cross-Site Scripting ↗2022-10-21 CVE-2021-36905 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 7.3.4 Patched in 7.3.5
- Medium · 6.4 Quiz And Survey Master <= 7.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting ↗2022-10-21 CVE-2021-36863 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 7.3.4 Patched in 7.3.5
- 2022-10-21 CVE-2022-42883 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 7.3.10 Patched in 7.3.11
- 2022-09-29 CVE-2021-36865 Authorization Bypass Through User-Controlled Key Affects <= 7.3.4 Patched in 7.3.5
- 2022-01-12 CVE-2022-0182 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 7.3.6 Patched in 7.3.7
- 2022-01-12 CVE-2022-0181 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 7.3.6 Patched in 7.3.7
- 2021-09-13 CVE-2021-24691 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 7.3.1 Patched in 7.3.2
- 2021-09-13 CVE-2021-20792 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 7.1.13 Patched in 7.1.14
- Medium · 6.1 Quiz and Survey Master <= 7.1.13 - SQL Injection ↗2021-08-10 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 7.1.13 Patched in 7.1.14
- 2021-06-03 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 7.1.19 Patched in 7.1.19
- 2021-06-03 CVE-2021-24368 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 7.1.17 Patched in 7.1.18
- 2021-03-26 CVE-2021-24221 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 7.1.11 Patched in 7.1.12
- Critical · 9.8 Quiz and Survey Master <= 7.0.1 - Arbitrary File Upload ↗2020-08-29 Unrestricted Upload of File with Dangerous Type Affects <= 7.0.1 Patched in 7.0.2
- 2020-08-03 CVE-2020-35951 Authorization Bypass Through User-Controlled Key Affects < 7.0.1 Patched in 7.0.1
- Critical · 9.8 Quiz and Survey Master <= 7.0.0 - Arbitrary File Upload ↗2020-08-03 CVE-2020-35949 Unrestricted Upload of File with Dangerous Type Affects < 7.0.1 Patched in 7.0.1
- 2020-07-29 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 6.4.12 Patched in 7.0.0
- 2019-11-13 CVE-2019-17599 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 6.3.4 Patched in 6.3.5
- 2019-03-05 CVE-2019-9575 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 6.2.1 Patched in 6.2.2
- 2015-07-16 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 4.4.4 Patched in 4.4.4
Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.
CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.
Behavioral tests
via WP HiveAutomated install-time checks, tested on PHP 8.1.12 · WP 7.0.1
Languages
via translate.wordpress.orgTranslated into 43 languages, 1 at 90% or more
Plus 19 more locales with partial translations.
Growth timeline
Install-tier crossings we have observed, and how long each tier took to outgrow
No tier crossings observed yet.
Competes with
The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).
-
Quiz Maker by AYS 20K+ installs · 4.9★ · 3 shared tags A -
HD Quiz 6K+ installs · 4.9★ · 3 shared tags A -
Quiz Maker, Poll Maker & Survey Maker by Opinion Stage 6K+ installs · 4.3★ · 3 shared tags A
-
Watu Quiz 3K+ installs · 4.6★ · 3 shared tags A -
Chained Quiz 1K+ installs · 4.7★ · 3 shared tags A -
SurveyJS: Drag & Drop Form Builder 500+ installs · 4.1★ · 3 shared tags B
Embed this report card
Drop a live Pulse card for Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker into a readme, a review or a deck. It updates itself.
<iframe src="https://plugins.wpmayor.com/embed/quiz-master-next" width="480" height="300" style="border:0" loading="lazy" title="Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker — Plugin Pulse"></iframe> Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker: 40K+ active installs, 4.7★ (1,280 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/quiz-master-next