
EngageBay Marketing Automation for LearnDash Security & Risk Analysis
wordpress.org/plugins/engagebay-add-on-for-learndashEffortlessly connect LearnDash with EngageBay CRM to supercharge student engagement. Automate email campaigns, segment users by course activity, and t …
Is EngageBay Marketing Automation for LearnDash Safe to Use in 2026?
Generally Safe
Score 100/100EngageBay Marketing Automation for LearnDash has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'engagebay-add-on-for-learndash' v1.1 plugin demonstrates a generally strong security posture, with good practices observed in its code. The absence of dangerous functions, SQL injection vulnerabilities (all queries use prepared statements), and proper output escaping are significant strengths. Furthermore, the plugin has no recorded vulnerabilities in its history, suggesting a well-maintained and secure codebase over time. However, there are notable areas of concern. The presence of one REST API route without permission callbacks presents a potential entry point for unauthorized access or data manipulation, as it is not adequately protected. While the total attack surface is small, this single unprotected endpoint is a critical weakness. The plugin also makes external HTTP requests, which, while not inherently a vulnerability, can introduce risks if the external endpoints are compromised or if data is not handled securely during these requests. The limited number of nonces and capability checks, combined with the unprotected REST API route, indicate room for improvement in access control and request validation.
Key Concerns
- REST API route without permission callbacks
- External HTTP requests present
- Limited capability checks
EngageBay Marketing Automation for LearnDash Security Vulnerabilities
EngageBay Marketing Automation for LearnDash Release Timeline
EngageBay Marketing Automation for LearnDash Code Analysis
Output Escaping
EngageBay Marketing Automation for LearnDash Attack Surface
REST API Routes 2
WordPress Hooks 19
Maintenance & Trust
EngageBay Marketing Automation for LearnDash Maintenance & Trust
Maintenance Signals
Community Trust
EngageBay Marketing Automation for LearnDash Alternatives
EngageBay WooCommerce Addon
engagebay-woocommerce-addon
Automate your eCommerce with WooCommerce + EngageBay — run smart campaigns, boost engagement, and personalize messaging to grow your business faster.
Himuon Integration for Klaviyo and Gravity Forms
himuon-integration-for-klaviyo-and-gravity-forms
An independent integration for Gravity Forms that securely creates or updates Klaviyo profiles and subscribes form entries to selected lists.
ActiveCampaign – The autonomous marketing platform
activecampaign-subscription-forms
Add ActiveCampaign contact forms and live chat to any post, page, or sidebar. Also enable ActiveCampaign site tracking for your WordPress blog.
Brevo for WooCommerce
woocommerce-sendinblue-newsletter-subscription
All-in-one WooCommerce email marketing, automation, SMS, and CRM by Brevo. Grow your store with powerful marketing tools.
FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce
wp-marketing-automations
Recover lost revenue with Cart Abandonment Recovery for WooCommerce. Increase retention with Post Purchase Follow-Up Emails.
EngageBay Marketing Automation for LearnDash Developer Profile
7 plugins · 430 total installs
How We Detect EngageBay Marketing Automation for LearnDash
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/engagebay-add-on-for-learndash/assets/css/admin-style.css/wp-content/plugins/engagebay-add-on-for-learndash/assets/js/admin-engagebay.js/wp-content/plugins/engagebay-add-on-for-learndash/assets/js/admin-engagebay.jsengagebay-add-on-for-learndash/assets/css/admin-style.css?ver=engagebay-add-on-for-learndash/assets/js/admin-engagebay.js?ver=HTML / DOM Fingerprints
EngageBay_LearnDash/wp-json/learndash-engagebay/get-nonce/wp-json/learndash-engagebay/deactivate