Addon for AB-Inspiration, WooCommerce and WP Courseware Security & Risk Analysis

wordpress.org/plugins/abwpwoo

Плагин добавляет дополнительные настройки на страницу Курсы созданную с помощью плагина WP Courseware и WooCommerce.

40 active installs v5.4 PHP + WP 4.8+ Updated May 26, 2024
ab-inspirationlearning-management-systemlmswoocommercewp-courseware
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Addon for AB-Inspiration, WooCommerce and WP Courseware Safe to Use in 2026?

Generally Safe

Score 92/100

Addon for AB-Inspiration, WooCommerce and WP Courseware has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The 'abwpwoo' plugin v5.4 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, SQL injection vulnerabilities, file operations, and external HTTP requests is highly commendable. Furthermore, all detected SQL queries utilize prepared statements, which is a crucial best practice for preventing SQL injection. The limited attack surface, with only two shortcodes identified as entry points and none requiring authentication checks, also contributes positively to its security.

However, a significant concern arises from the low percentage of properly escaped output. With only 13% of 32 total outputs being properly escaped, there is a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. This means that malicious scripts could potentially be injected into the website through user-supplied data that is displayed without adequate sanitization or encoding. The complete lack of nonce checks and capability checks on any identified entry points is another critical weakness. This indicates that there are no mechanisms in place to verify the legitimacy of requests or the user's authorization, potentially allowing unauthorized actions.

The plugin's vulnerability history, showing zero known CVEs, is a positive indicator, suggesting a history of stability. However, this should not be interpreted as complete immunity, especially in light of the identified output escaping and authorization weaknesses. The conclusion is that while 'abwpwoo' v5.4 has good fundamentals in areas like SQL query handling and a small attack surface, the severe lack of output escaping and authorization checks presents a significant and actionable security risk that needs immediate attention.

Key Concerns

  • Insufficient output escaping (XSS risk)
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Addon for AB-Inspiration, WooCommerce and WP Courseware Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Addon for AB-Inspiration, WooCommerce and WP Courseware Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
28
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

13% escaped32 total outputs
Attack Surface

Addon for AB-Inspiration, WooCommerce and WP Courseware Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[wpb_gravatar] wwpcouseware-extra-settings.php:262
[wpcourse_enroll_link] wwpcouseware-extra-settings.php:335
WordPress Hooks 6
actionplugins_loadedwwpcouseware-extra-settings.php:18
actionwp_enqueue_scriptswwpcouseware-extra-settings.php:33
actionadmin_initwwpcouseware-extra-settings.php:42
actionadmin_menuwwpcouseware-extra-settings.php:46
filterwpcw_ignore_active_membership_integrationwwpcouseware-extra-settings.php:264
filterwpcw_course_enrollment_success_messagewwpcouseware-extra-settings.php:266
Maintenance & Trust

Addon for AB-Inspiration, WooCommerce and WP Courseware Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedMay 26, 2024
PHP min version
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs40
Developer Profile

Addon for AB-Inspiration, WooCommerce and WP Courseware Developer Profile

Anfisa Breus

1 plugin · 40 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Addon for AB-Inspiration, WooCommerce and WP Courseware

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/abwpwoo/js/wpcw-custom.js
Script Paths
/wp-content/plugins/abwpwoo/js/wpcw-custom.js

HTML / DOM Fingerprints

CSS Classes
wpcw_custom
Data Attributes
name="ab_wpcourseware[id_courses][]"name="ab_wpcourseware[id_courses_courses][]"name="ab_wpcourseware[id_courses_product][]"name="ab_wpcourseware[id_courses_pages][]"name="ab_wpcourseware[id_courses_courses_pages][]"
JS Globals
course_complete
FAQ

Frequently Asked Questions about Addon for AB-Inspiration, WooCommerce and WP Courseware