
Easy Classes Security & Risk Analysis
wordpress.org/plugins/easy-classesThis plugin has been made to easily handle classes and teachers informations on a Wordpress website.
Is Easy Classes Safe to Use in 2026?
Generally Safe
Score 85/100Easy Classes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'easy-classes' plugin v1.2 presents a mixed security posture. While it boasts a clean attack surface with no apparent entry points like AJAX handlers, REST API routes, or shortcodes, and shows good practices in using prepared statements for SQL queries and implementing nonce and capability checks, there are significant concerns regarding output escaping and the presence of dangerous functions.
The static analysis reveals that 100% of the outputs are not properly escaped, which is a critical security flaw. This means that any user-supplied data that is outputted by the plugin could potentially be rendered as executable code (e.g., JavaScript) in the user's browser, leading to cross-site scripting (XSS) vulnerabilities. Additionally, the use of the `unserialize` function without adequate sanitization of the input data poses a risk of arbitrary object injection and potential remote code execution if the serialized data can be controlled by an attacker.
The plugin's vulnerability history is currently clean, with no recorded CVEs. This is a positive sign, but it does not negate the risks identified in the static analysis. The lack of historical vulnerabilities might simply mean that these specific types of flaws have not been exploited or discovered in this plugin's past versions, or that the plugin has not been subjected to extensive security auditing until now. The current findings, particularly the output escaping and `unserialize` risks, require immediate attention to secure the plugin effectively.
Key Concerns
- Unescaped output across all outputs
- Dangerous function: unserialize used
Easy Classes Security Vulnerabilities
Easy Classes Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Easy Classes Attack Surface
WordPress Hooks 4
Maintenance & Trust
Easy Classes Maintenance & Trust
Maintenance Signals
Community Trust
Easy Classes Alternatives
UORS External Course List
uors-external-course-list
This plugin adds a "Quick Reserve" widget to your wordpress weblog sidebar. With this widget you can display a list of services that you pr …
MB Spirit for MINDBODY
mb-spirit-for-mindbody
Connect your MB Spirit account with WordPress for easy integration of your MINDBODY account information and enhance SEO support.
Gym Studio Membership Management
gym-studio-membership-management
Gym Studio Membership Management adds class calendar, schedule of classes and membership checkout to your posts and pages.
Kenzap Timetable
kenzap-timetable
A beautiful and easy customizable set of Gutenberg blocks to create timetable, school calendars, publish lessons online or create timeline or yoga cou …
Automaize Class Schedule
automaize-class-schedule
A powerful and intuitive solution for managing and displaying class schedules with a seamless booking experience for members.
Easy Classes Developer Profile
1 plugin · 10 total installs
How We Detect Easy Classes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/easy-classes/css/easy-classes.css/wp-content/plugins/easy-classes/js/easy-classes.js/wp-content/plugins/easy-classes/js/easy-classes.jseasy-classes/css/easy-classes.css?ver=easy-classes/js/easy-classes.js?ver=HTML / DOM Fingerprints
eac-classeac-teacher