Oxygen Tutor LMS Security & Risk Analysis

wordpress.org/plugins/oxygen-tutor-lms

Build E-Learning website by Oxygen Builder and Tutor LMS Integration plugin

300 active installs v2.0.3 PHP 7.4+ WP 5.3+ Updated Apr 18, 2023
courseelearninglearning-management-systemlmsoxygen-builder
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Oxygen Tutor LMS Safe to Use in 2026?

Generally Safe

Score 85/100

Oxygen Tutor LMS has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The oxygen-tutor-lms plugin v2.0.3 exhibits a generally good security posture with no recorded vulnerabilities or critical security flaws identified in the static and taint analysis. The absence of direct SQL queries without prepared statements, file operations, and external HTTP requests are positive indicators of secure coding practices. The presence of capability checks and a majority of properly escaped outputs further strengthen its security. However, a significant concern arises from the taint analysis, which revealed two flows with unsanitized paths. While these did not escalate to critical or high severity in this analysis, unsanitized paths can be a precursor to vulnerabilities if not addressed. The lack of AJAX handlers, REST API routes, shortcodes, and cron events, while reducing the attack surface, also means there are no explicit entry points to assess for nonce or permission checks, making it difficult to fully evaluate the security of potential future features. The plugin's clean vulnerability history is a strong point, suggesting a commitment to security by the developers, but the identified taint flows warrant attention for future development or updates to ensure a robust security profile.

Key Concerns

  • Flows with unsanitized paths
  • Output escaping only 69% proper
  • No nonce checks found
Vulnerabilities
None known

Oxygen Tutor LMS Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Oxygen Tutor LMS Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
55
123 escaped
Nonce Checks
0
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

69% escaped178 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

3 flows2 with unsanitized paths
<login> (templates\login.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Oxygen Tutor LMS Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 14
filtertutor_lms_should_template_overrideoxygen-tutor-lms.php:39
actioninitoxygen-tutor-lms.php:47
actionplugins_loadedoxygen-tutor-lms.php:54
actionwp_enqueue_scriptsoxygen-tutor-lms.php:64
filtertutor_get_template_pathOxygenTutorLMS.php:34
actionoxygen_add_plus_sectionsOxygenTutorLMS.php:39
actionoxygen_add_plus_tutor_section_contentOxygenTutorLMS.php:43
actionpre_get_postsOxygenTutorLMS.php:46
actiontemplate_redirectOxygenTutorLMS.php:48
actionadmin_noticesOxygenTutorLMS.php:183
actionadmin_noticesOxygenTutorLMS.php:187
actionadmin_noticesOxygenTutorLMS.php:192
filtercourses_col_per_rowtemplates\public-profile.php:172
filterwp_kses_allowed_htmltemplates\single-content-loader.php:43
Maintenance & Trust

Oxygen Tutor LMS Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedApr 18, 2023
PHP min version7.4
Downloads15K

Community Trust

Rating76/100
Number of ratings4
Active installs300
Developer Profile

Oxygen Tutor LMS Developer Profile

Themeum

14 plugins · 675K total installs

70
trust score
Avg Security Score
87/100
Avg Patch Time
269 days
View full developer profile
Detection Fingerprints

How We Detect Oxygen Tutor LMS

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/oxygen-tutor-lms/assets/css/public.css

HTML / DOM Fingerprints

CSS Classes
tutor-courses-wraptutor-course-filter-containertutor-course-filtertutor-widgettutor-widget-titletutor-list-itemtutor-course-listtutor-course-card+16 more
Data Attributes
data-plugin-name="OxygenTutorLMS"
FAQ

Frequently Asked Questions about Oxygen Tutor LMS