
Lesson Bookmark for Tutor LMS Security & Risk Analysis
wordpress.org/plugins/lesson-bookmark-tutor-lmsLesson Bookmark allows you to add lessons in the list of your favorite lessons and to display the favorites with [tllb_display_favorites]
Is Lesson Bookmark for Tutor LMS Safe to Use in 2026?
Generally Safe
Score 92/100Lesson Bookmark for Tutor LMS has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
This plugin, lesson-bookmark-tutor-lms v2.0.3, exhibits a mixed security posture with some concerning elements despite a clean vulnerability history. The presence of two AJAX handlers without authentication checks is a significant weakness, creating an easily exploitable attack surface. Additionally, the use of the `unserialize` function is a red flag, as it can lead to deserialization vulnerabilities if the input is not strictly controlled and sanitized, which is not explicitly demonstrated as being done here. The limited output escaping also raises concerns about potential cross-site scripting (XSS) vulnerabilities in a portion of the plugin's output.
Key Concerns
- AJAX handlers without authentication
- Use of unserialize function
- Low percentage of properly escaped output
- No capability checks on entry points
Lesson Bookmark for Tutor LMS Security Vulnerabilities
Lesson Bookmark for Tutor LMS Code Analysis
Dangerous Functions Found
Output Escaping
Lesson Bookmark for Tutor LMS Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 11
Maintenance & Trust
Lesson Bookmark for Tutor LMS Maintenance & Trust
Maintenance Signals
Community Trust
Lesson Bookmark for Tutor LMS Alternatives
No alternatives data available yet.
Lesson Bookmark for Tutor LMS Developer Profile
2 plugins · 700 total installs
How We Detect Lesson Bookmark for Tutor LMS
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lesson-bookmark-tutor-lms/admin/css/tutor-lms-lesson-bookmark-admin.css/wp-content/plugins/lesson-bookmark-tutor-lms/admin/js/tutor-lms-lesson-bookmark-admin.jsadmin/js/tutor-lms-lesson-bookmark-admin.jstutor-lms-lesson-bookmark-admintutor-lms-lesson-bookmark-adminHTML / DOM Fingerprints
tllb_review_noticetllb_hide_noticedata-duration[tllb_display_favorites]