EduAdmin – SveaWebPay WordPress-plugin Security & Risk Analysis

wordpress.org/plugins/eduadmin-sveawebpay

EduAdmin - SveaWebPay WordPress-plugin

0 active installs v3.0.1 PHP 5.2+ WP 5.0+ Updated Unknown
bookingcourseseduadmineventsparticipants
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is EduAdmin – SveaWebPay WordPress-plugin Safe to Use in 2026?

Generally Safe

Score 100/100

EduAdmin – SveaWebPay WordPress-plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The eduadmin-sveawebpay plugin version 3.0.1 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, SQL queries without prepared statements, file operations, and external HTTP requests are all positive indicators. Furthermore, the high percentage of properly escaped output suggests good practices in preventing cross-site scripting (XSS) vulnerabilities. The plugin also demonstrates a clean vulnerability history with no recorded CVEs.

However, there are areas that warrant attention. The complete absence of nonce checks across all entry points is a significant concern. While the plugin does have one capability check, this single check may not be sufficient to protect all functionalities. The lack of taint analysis results is also noted, though this may simply mean no flows were identified during the analysis. The limited attack surface is a positive, but the lack of specific authentication or authorization on the shortcode, despite it being the only entry point identified without explicit auth checks, could present a risk if it handles sensitive data or performs critical actions.

In conclusion, the plugin has implemented several robust security measures. Nevertheless, the lack of nonce checks on all entry points and the potential for the shortcode to be inadequately protected require further investigation. The absence of known vulnerabilities is a strong positive, but it is crucial to ensure that the current security practices, particularly regarding input validation and authorization, are comprehensive enough to prevent future issues.

Key Concerns

  • No nonce checks on entry points
  • Single capability check may not cover all entry points
  • Shortcode without explicit auth check identified
Vulnerabilities
None known

EduAdmin – SveaWebPay WordPress-plugin Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

EduAdmin – SveaWebPay WordPress-plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
14 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

93% escaped15 total outputs
Attack Surface

EduAdmin – SveaWebPay WordPress-plugin Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[eduadmin-svea-testpage] class\class-edu-sveawebpay.php:32
WordPress Hooks 8
actioneduadmin-checkpaymentpluginsclass\class-edu-sveawebpay.php:27
actioneduadmin-processbookingclass\class-edu-sveawebpay.php:28
actioneduadmin-bookingcompletedclass\class-edu-sveawebpay.php:29
actionwp_loadedclass\class-edu-sveawebpay.php:30
actionadmin_initeduadmin-wordpress-sveawebpay.php:38
actionadmin_noticeseduadmin-wordpress-sveawebpay.php:41
actionplugins_loadededuadmin-wordpress-sveawebpay.php:59
filteredu_integrationseduadmin-wordpress-sveawebpay.php:67
Maintenance & Trust

EduAdmin – SveaWebPay WordPress-plugin Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedUnknown
PHP min version5.2
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

EduAdmin – SveaWebPay WordPress-plugin Developer Profile

Chris Gardenberg

5 plugins · 50 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
9 days
View full developer profile
Detection Fingerprints

How We Detect EduAdmin – SveaWebPay WordPress-plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/eduadmin-sveawebpay/css/eduadmin-sveawebpay.css/wp-content/plugins/eduadmin-sveawebpay/js/eduadmin-sveawebpay.js
Script Paths
/wp-content/plugins/eduadmin-sveawebpay/js/eduadmin-sveawebpay.js
Version Parameters
eduadmin-sveawebpay/css/eduadmin-sveawebpay.css?ver=eduadmin-sveawebpay/js/eduadmin-sveawebpay.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-nonce
JS Globals
EDU
Shortcode Output
[eduadmin-svea-testpage]
FAQ

Frequently Asked Questions about EduAdmin – SveaWebPay WordPress-plugin