
Addon for AB-Inspiration, WooCommerce and WP Courseware Security & Risk Analysis
wordpress.org/plugins/abwpwooПлагин добавляет дополнительные настройки на страницу Курсы созданную с помощью плагина WP Courseware и WooCommerce.
Is Addon for AB-Inspiration, WooCommerce and WP Courseware Safe to Use in 2026?
Generally Safe
Score 92/100Addon for AB-Inspiration, WooCommerce and WP Courseware has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'abwpwoo' plugin v5.4 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, SQL injection vulnerabilities, file operations, and external HTTP requests is highly commendable. Furthermore, all detected SQL queries utilize prepared statements, which is a crucial best practice for preventing SQL injection. The limited attack surface, with only two shortcodes identified as entry points and none requiring authentication checks, also contributes positively to its security.
However, a significant concern arises from the low percentage of properly escaped output. With only 13% of 32 total outputs being properly escaped, there is a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. This means that malicious scripts could potentially be injected into the website through user-supplied data that is displayed without adequate sanitization or encoding. The complete lack of nonce checks and capability checks on any identified entry points is another critical weakness. This indicates that there are no mechanisms in place to verify the legitimacy of requests or the user's authorization, potentially allowing unauthorized actions.
The plugin's vulnerability history, showing zero known CVEs, is a positive indicator, suggesting a history of stability. However, this should not be interpreted as complete immunity, especially in light of the identified output escaping and authorization weaknesses. The conclusion is that while 'abwpwoo' v5.4 has good fundamentals in areas like SQL query handling and a small attack surface, the severe lack of output escaping and authorization checks presents a significant and actionable security risk that needs immediate attention.
Key Concerns
- Insufficient output escaping (XSS risk)
- Missing nonce checks
- Missing capability checks
Addon for AB-Inspiration, WooCommerce and WP Courseware Security Vulnerabilities
Addon for AB-Inspiration, WooCommerce and WP Courseware Code Analysis
Output Escaping
Addon for AB-Inspiration, WooCommerce and WP Courseware Attack Surface
Shortcodes 2
WordPress Hooks 6
Maintenance & Trust
Addon for AB-Inspiration, WooCommerce and WP Courseware Maintenance & Trust
Maintenance Signals
Community Trust
Addon for AB-Inspiration, WooCommerce and WP Courseware Alternatives
Learning Objects LMS
learning-objects-lms
Learning Objects LMS is a plugin for Woocommerce that allows you to connect your shop or website to the professional Learning Objects environment for …
Tutor LMS – eLearning and online course solution
tutor
A complete WordPress LMS plugin to create any eLearning website easily.
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses
learnpress
A WordPress LMS Plugin to create WordPress Learning Management System. Turn your WordPress to LMS WordPress Website with Courses, Lessons, Quizzes &am …
LearnPress – Course Review
learnpress-course-review
LearnPress Course Review - An extension plugin for LearnPress.
Tutor LMS Elementor Addons
tutor-lms-elementor-addons
Get 35+ Elementor widgets to create an entire eLearning site with Tutor LMS and design custom course pages, course carousels, listings, and more.
Addon for AB-Inspiration, WooCommerce and WP Courseware Developer Profile
1 plugin · 40 total installs
How We Detect Addon for AB-Inspiration, WooCommerce and WP Courseware
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/abwpwoo/js/wpcw-custom.js/wp-content/plugins/abwpwoo/js/wpcw-custom.jsHTML / DOM Fingerprints
wpcw_customname="ab_wpcourseware[id_courses][]"name="ab_wpcourseware[id_courses_courses][]"name="ab_wpcourseware[id_courses_product][]"name="ab_wpcourseware[id_courses_pages][]"name="ab_wpcourseware[id_courses_courses_pages][]"course_complete