Saksh private IELTS preparation Security & Risk Analysis

wordpress.org/plugins/saksh-private-ielts-preparation

This plugin provide around 3000+ questions/anwer set to your students for the practise for the IELTS. [PrivateIELTSEXCERCISE]

10 active installs v4.1.1 PHP + WP 2.7+ Updated Jun 17, 2024
exam-softwareieltsielts-testprivate-ielts-study
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Saksh private IELTS preparation Safe to Use in 2026?

Generally Safe

Score 92/100

Saksh private IELTS preparation has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The saksh-private-ielts-preparation plugin, version 4.1.1, exhibits a mixed security posture. On the positive side, it has no known vulnerabilities (CVEs) and no external HTTP requests or file operations, which are common vectors for compromise. The plugin also utilizes prepared statements for all its SQL queries, a strong indicator of good database security practices. However, several concerning signals emerge from the static analysis. The most significant concern is the lack of any capability checks or nonce checks across its identified entry points, including a shortcode. This means that any user, regardless of their role or authentication status, could potentially interact with the plugin's functionality. Furthermore, the taint analysis revealed two flows with unsanitized paths, indicating a potential for path traversal or local file inclusion vulnerabilities, even though they are not classified as critical or high severity in this analysis. The low percentage of properly escaped output (4%) is also a significant concern, suggesting a high risk of Cross-Site Scripting (XSS) vulnerabilities across its outputs.

While the plugin's history of zero CVEs is reassuring, it does not negate the immediate risks identified in the code analysis. The absence of vulnerabilities in the past could be due to luck, infrequent auditing, or a lack of exploitation attempts. The current static analysis highlights a considerable risk of XSS due to insufficient output escaping and potential path-related vulnerabilities. The lack of authorization checks on its single entry point is a critical oversight. Therefore, despite the absence of known CVEs and good SQL practices, the plugin's current version presents significant security risks that require immediate attention, particularly regarding output escaping and access control.

Key Concerns

  • Unsanitized paths in taint flows
  • Insufficient output escaping (96% unescaped)
  • No capability checks on entry points
  • No nonce checks on entry points
Vulnerabilities
None known

Saksh private IELTS preparation Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Saksh private IELTS preparation Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
25
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

4% escaped26 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
saksh_private_ielts_preparation__excersize_func (saksh_private_ielts_preparation_shortcode.php:4)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Saksh private IELTS preparation Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[PrivateIELTSEXCERCISE] saksh_private_ielts_preparation_shortcode.php:158
WordPress Hooks 2
actionwp_enqueue_scriptsindex.php:55
actionadmin_menusaksh_private_ielts_preparation_support.php:24
Maintenance & Trust

Saksh private IELTS preparation Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedJun 17, 2024
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Alternatives

Saksh private IELTS preparation Alternatives

No alternatives data available yet.

Developer Profile

Saksh private IELTS preparation Developer Profile

susheelhbti

14 plugins · 40 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Saksh private IELTS preparation

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/saksh-private-ielts-preparation/saksh.css/wp-content/plugins/saksh-private-ielts-preparation/saksh.js
Version Parameters
saksh-private-ielts-preparation/saksh.css?ver=saksh-private-ielts-preparation/saksh.js?ver=

HTML / DOM Fingerprints

CSS Classes
sakshh3sakshtabletogglebtn
Data Attributes
data-toggledata-target
Shortcode Output
<div id="sakshaccordion"><table class="sakshtable table table-hover"><th>Excercise ID</th><th>Title</th>
FAQ

Frequently Asked Questions about Saksh private IELTS preparation