
Sertifier Certificate & Badge Maker for WordPress – Tutor LMS Security & Risk Analysis
wordpress.org/plugins/sertifier-certificates-open-badgesEasily create professional certificates and badges for every course or training you offer on WordPress. Give your students an exciting way to showcase …
Is Sertifier Certificate & Badge Maker for WordPress – Tutor LMS Safe to Use in 2026?
Mostly Safe
Score 77/100Sertifier Certificate & Badge Maker for WordPress – Tutor LMS is generally safe to use. 2 past CVEs were resolved. Keep it updated.
The "sertifier-certificates-open-badges" v1.21 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals strong adherence to secure coding practices. The attack surface is relatively small with all identified entry points (AJAX handlers) being protected by authentication checks. The plugin also demonstrates good data handling, with a high percentage of SQL queries using prepared statements and outputs being properly escaped. File operations and dangerous functions are absent, which are excellent indicators of security awareness.
However, the plugin's vulnerability history is a significant concern. It has a history of two known CVEs, with one currently unpatched. These past vulnerabilities were identified as Cross-Site Request Forgery (CSRF) and Missing Authorization, indicating potential weaknesses in how user actions and permissions are handled. The fact that a vulnerability was patched as recently as August 2025 suggests ongoing security challenges or a recent discovery. While taint analysis showed no critical or high-severity issues, the historical pattern of authorization and CSRF vulnerabilities, coupled with the unpatched CVE, elevates the overall risk.
In conclusion, while the current version's code analysis shows good security practices in isolation, the persistent history of medium-severity authorization and CSRF vulnerabilities, particularly the unpatched one, presents a notable risk. Administrators should prioritize addressing the unpatched CVE and remain vigilant about potential future security issues stemming from these recurring vulnerability types.
Key Concerns
- Unpatched CVE
- Historical CSRF vulnerabilities
- Historical Missing Authorization vulnerabilities
Sertifier Certificate & Badge Maker for WordPress – Tutor LMS Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Sertifier Certificate & Badge Maker for WordPress – Tutor LMS <= 1.19 - Cross-Site Request Forgery to Settings Update
Sertifier Certificate & Badge Maker <= 1.21 - Missing Authorization
Sertifier Certificate & Badge Maker for WordPress – Tutor LMS Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Sertifier Certificate & Badge Maker for WordPress – Tutor LMS Attack Surface
AJAX Handlers 4
WordPress Hooks 13
Maintenance & Trust
Sertifier Certificate & Badge Maker for WordPress – Tutor LMS Maintenance & Trust
Maintenance Signals
Community Trust
Sertifier Certificate & Badge Maker for WordPress – Tutor LMS Alternatives
IssueBadge – Bulk Certificate Generator
issuebadge-bulk-certificate-generator
Generate and issue digital certificates and badges using the IssueBadge API directly from your WordPress admin panel.
Advanced Product Labels for WooCommerce
advanced-product-labels-for-woocommerce
Promote exclusive discounts, new products or free shipping. Create labels easily and quickly!
PW WooCommerce Gift Cards
pw-woocommerce-gift-cards
Sell gift cards to your WooCommerce store, in just a few minutes!
Product Labels For Woocommerce (Sale Badges)
aco-product-labels-for-woocommerce
Create custom product labels and sale badges for WooCommerce products to highlight offers and promotions.
Advanced Woo Labels – Product Labels & Badges for WooCommerce
advanced-woo-labels
Labels plugin for WooCommerce. Create labels/badges with custom styles and text for any of your WooCommerce products.
Sertifier Certificate & Badge Maker for WordPress – Tutor LMS Developer Profile
1 plugin · 60 total installs
How We Detect Sertifier Certificate & Badge Maker for WordPress – Tutor LMS
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sertifier-certificates-open-badges/assets/css/style.css/wp-content/plugins/sertifier-certificates-open-badges/assets/js/admin.js/wp-content/plugins/sertifier-certificates-open-badges/assets/js/admin.jssertifier-certificates-open-badges/assets/css/style.css?ver=sertifier-certificates-open-badges/assets/js/admin.js?ver=HTML / DOM Fingerprints
data-sertifier-emaildata-sertifier-tokenplugin_ajax_object/wp-json/sertifier/v1/get_settings/wp-json/sertifier/v1/save_settings/wp-json/sertifier/v1/get_issues/wp-json/sertifier/v1/add_issue/wp-json/sertifier/v1/delete_issue[sertifier_display_certificate][sertifier_display_badge]