
EngageBay Marketing Automation for LearnDash Security & Risk Analysis
wordpress.org/plugins/engagebay-add-on-for-learndashEffortlessly connect LearnDash with EngageBay CRM to supercharge student engagement. Automate email campaigns, segment users by course activity, and t …
Is EngageBay Marketing Automation for LearnDash Safe to Use in 2026?
Generally Safe
Score 100/100EngageBay Marketing Automation for LearnDash has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'engagebay-add-on-for-learndash' v1.1 plugin demonstrates a generally strong security posture, with good practices observed in its code. The absence of dangerous functions, SQL injection vulnerabilities (all queries use prepared statements), and proper output escaping are significant strengths. Furthermore, the plugin has no recorded vulnerabilities in its history, suggesting a well-maintained and secure codebase over time. However, there are notable areas of concern. The presence of one REST API route without permission callbacks presents a potential entry point for unauthorized access or data manipulation, as it is not adequately protected. While the total attack surface is small, this single unprotected endpoint is a critical weakness. The plugin also makes external HTTP requests, which, while not inherently a vulnerability, can introduce risks if the external endpoints are compromised or if data is not handled securely during these requests. The limited number of nonces and capability checks, combined with the unprotected REST API route, indicate room for improvement in access control and request validation.
Key Concerns
- REST API route without permission callbacks
- External HTTP requests present
- Limited capability checks
EngageBay Marketing Automation for LearnDash Security Vulnerabilities
EngageBay Marketing Automation for LearnDash Code Analysis
Output Escaping
EngageBay Marketing Automation for LearnDash Attack Surface
REST API Routes 2
WordPress Hooks 19
Maintenance & Trust
EngageBay Marketing Automation for LearnDash Maintenance & Trust
Maintenance Signals
Community Trust
EngageBay Marketing Automation for LearnDash Alternatives
ActiveCampaign – The autonomous marketing platform
activecampaign-subscription-forms
Add ActiveCampaign contact forms and live chat to any post, page, or sidebar. Also enable ActiveCampaign site tracking for your WordPress blog.
Brevo for WooCommerce
woocommerce-sendinblue-newsletter-subscription
All-in-one WooCommerce email marketing, automation, SMS, and CRM by Brevo. Grow your store with powerful marketing tools.
FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce
wp-marketing-automations
Recover lost revenue with Cart Abandonment Recovery for WooCommerce. Increase retention with Post Purchase Follow-Up Emails.
MWB HubSpot for WooCommerce – CRM, Abandoned Cart, Email Marketing, Marketing Automation & Analytics
makewebbetter-hubspot-for-woocommerce
Integrate WooCommerce with HubSpot’s free CRM, abandoned cart tracking, email marketing, marketing automation, analytics & more.
CleverReach® WP
cleverreach-wp
Connect your WordPress account with our easy-to-use email software and increase the success of your website or blog with newsletter marketing!
EngageBay Marketing Automation for LearnDash Developer Profile
6 plugins · 400 total installs
How We Detect EngageBay Marketing Automation for LearnDash
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/engagebay-add-on-for-learndash/assets/css/admin-style.css/wp-content/plugins/engagebay-add-on-for-learndash/assets/js/admin-engagebay.js/wp-content/plugins/engagebay-add-on-for-learndash/assets/js/admin-engagebay.jsengagebay-add-on-for-learndash/assets/css/admin-style.css?ver=engagebay-add-on-for-learndash/assets/js/admin-engagebay.js?ver=HTML / DOM Fingerprints
EngageBay_LearnDash/wp-json/learndash-engagebay/get-nonce/wp-json/learndash-engagebay/deactivate