eFront Security & Risk Analysis

wordpress.org/plugins/efrontpro

This plugin integrates eFront with Wordpress. Promote your eFront content through your WordPress site.

0 active installs v1.2.2 PHP + WP 4.0+ Updated Nov 1, 2018
efrontlearning-management-systemlmsonline-learning-solutiononline-training-system
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is eFront Safe to Use in 2026?

Generally Safe

Score 85/100

eFront has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "efrontpro" v1.2.2 plugin exhibits a generally good security posture based on the provided static analysis. The absence of known CVEs and a clean vulnerability history are strong indicators of past security diligence. The plugin also demonstrates good practices by incorporating nonce checks and capability checks for its entry points, and a significant majority of its SQL queries utilize prepared statements. However, the analysis does reveal some areas for concern that could be exploited in a targeted attack.

The primary weakness lies in the output escaping. With only 33% of outputs properly escaped, there's a significant risk of Cross-Site Scripting (XSS) vulnerabilities, especially if user-supplied data is incorporated into these unescaped outputs. Furthermore, the taint analysis indicates one flow with unsanitized paths, which, although not flagged as critical or high severity, warrants investigation as it represents a potential entry point for malicious data. The presence of bundled libraries, specifically DataTables v1.10.15, also introduces a potential risk if this version has known vulnerabilities that are not mitigated within the plugin itself.

In conclusion, while "efrontpro" v1.2.2 benefits from a clean vulnerability history and good fundamental security practices like nonce and capability checks, the insufficient output escaping and the identified unsanitized path flow present tangible risks. Addressing these specific code-level concerns should be the priority to further harden the plugin's security.

Key Concerns

  • Insufficient output escaping
  • Flow with unsanitized path
  • Bundled outdated library (DataTables v1.10.15)
Vulnerabilities
None known

eFront Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

eFront Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

eFront Code Analysis

Dangerous Functions
0
Raw SQL Queries
4
15 prepared
Unescaped Output
27
13 escaped
Nonce Checks
7
Capability Checks
4
File Operations
2
External Requests
1
Bundled Libraries
1

Bundled Libraries

DataTables1.10.15

SQL Query Safety

79% prepared19 total queries

Output Escaping

33% escaped40 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

4 flows1 with unsanitized paths
efnt_setupPage (admin/admin.php:56)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

eFront Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 1

authwp_ajax_eF_resynchadmin/admin.php:151

Shortcodes 1

[efrontpro-courses] shortcodes/reg_shortcodes.php:29
WordPress Hooks 7
actionadmin_menuadmin/admin.php:17
actionadmin_enqueue_scriptsadmin/admin.php:38
filtercontextual_helpadmin/admin.php:45
actionadmin_noticesadmin/admin.php:164
actionadmin_initefrontpro.php:40
actionwoocommerce_created_customerintegrations/woocommerce.php:32
actionwoocommerce_order_status_completedintegrations/woocommerce.php:53
Maintenance & Trust

eFront Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.33
Last updatedNov 1, 2018
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

eFront Developer Profile

epignosis

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect eFront

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/efrontpro/admin/js/ef-admin.js/wp-content/plugins/efrontpro/admin/css/ef-admin.css
Script Paths
/wp-content/plugins/efrontpro/admin/js/ef-admin.js
Version Parameters
ef-adminef-admin

HTML / DOM Fingerprints

CSS Classes
efrontpro-warning
Data Attributes
data-nonce-fielddata-nonce-actiondata-nonce-valuedata-iddata-actiondata-security
JS Globals
translations
FAQ

Frequently Asked Questions about eFront