Sertifier Certificate & Badge Maker for WordPress – Tutor LMS Security & Risk Analysis

wordpress.org/plugins/sertifier-certificates-open-badges

Easily create professional certificates and badges for every course or training you offer on WordPress. Give your students an exciting way to showcase …

60 active installs v1.21 PHP 7.0+ WP 4.7+ Updated Sep 11, 2025
badgescertificatescredentialssertifier
77
B · Generally Safe
CVEs total2
Unpatched1
Last CVEAug 22, 2025
Safety Verdict

Is Sertifier Certificate & Badge Maker for WordPress – Tutor LMS Safe to Use in 2026?

Mostly Safe

Score 77/100

Sertifier Certificate & Badge Maker for WordPress – Tutor LMS is generally safe to use. 2 past CVEs were resolved. Keep it updated.

2 known CVEs 1 unpatched Last CVE: Aug 22, 2025Updated 6mo ago
Risk Assessment

The "sertifier-certificates-open-badges" v1.21 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals strong adherence to secure coding practices. The attack surface is relatively small with all identified entry points (AJAX handlers) being protected by authentication checks. The plugin also demonstrates good data handling, with a high percentage of SQL queries using prepared statements and outputs being properly escaped. File operations and dangerous functions are absent, which are excellent indicators of security awareness.

However, the plugin's vulnerability history is a significant concern. It has a history of two known CVEs, with one currently unpatched. These past vulnerabilities were identified as Cross-Site Request Forgery (CSRF) and Missing Authorization, indicating potential weaknesses in how user actions and permissions are handled. The fact that a vulnerability was patched as recently as August 2025 suggests ongoing security challenges or a recent discovery. While taint analysis showed no critical or high-severity issues, the historical pattern of authorization and CSRF vulnerabilities, coupled with the unpatched CVE, elevates the overall risk.

In conclusion, while the current version's code analysis shows good security practices in isolation, the persistent history of medium-severity authorization and CSRF vulnerabilities, particularly the unpatched one, presents a notable risk. Administrators should prioritize addressing the unpatched CVE and remain vigilant about potential future security issues stemming from these recurring vulnerability types.

Key Concerns

  • Unpatched CVE
  • Historical CSRF vulnerabilities
  • Historical Missing Authorization vulnerabilities
Vulnerabilities
2

Sertifier Certificate & Badge Maker for WordPress – Tutor LMS Security Vulnerabilities

CVEs by Year

2 CVEs in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2025-7841medium · 4.3Cross-Site Request Forgery (CSRF)

Sertifier Certificate & Badge Maker for WordPress – Tutor LMS <= 1.19 - Cross-Site Request Forgery to Settings Update

Aug 22, 2025 Patched in 1.20 (6d)
CVE-2025-53214medium · 4.3Missing Authorization

Sertifier Certificate & Badge Maker <= 1.21 - Missing Authorization

Jun 27, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Sertifier Certificate & Badge Maker for WordPress – Tutor LMS Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
20 prepared
Unescaped Output
5
85 escaped
Nonce Checks
7
Capability Checks
7
File Operations
0
External Requests
4
Bundled Libraries
0

SQL Query Safety

95% prepared21 total queries

Output Escaping

94% escaped90 total outputs
Data Flows
All sanitized

Data Flow Analysis

8 flows
get_lessons (classes\ajax.php:15)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Sertifier Certificate & Badge Maker for WordPress – Tutor LMS Attack Surface

Entry Points4
Unprotected0

AJAX Handlers 4

authwp_ajax_get_lessonsclasses\ajax.php:8
authwp_ajax_get_usersclasses\ajax.php:9
authwp_ajax_delete_auto_issuepages\AutoIssues.php:8
authwp_ajax_delete_manual_issuepages\ManualIssues.php:8
WordPress Hooks 13
actionadmin_menupages\AutoAddOrUpdate.php:8
actionadmin_enqueue_scriptspages\AutoAddOrUpdate.php:10
actionadmin_menupages\AutoIssues.php:6
actionadmin_menupages\Home.php:6
actionadmin_menupages\ManualAddOrUpdate.php:8
actionadmin_enqueue_scriptspages\ManualAddOrUpdate.php:10
actionadmin_menupages\ManualIssues.php:6
actionadmin_menupages\Settings.php:6
actionadmin_initpages\Settings.php:7
actionadmin_menusertifier.php:22
actionadmin_enqueue_scriptssertifier.php:23
actiontutor_course_complete_aftersertifier.php:107
actiontutor_lesson_completed_aftersertifier.php:108
Maintenance & Trust

Sertifier Certificate & Badge Maker for WordPress – Tutor LMS Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 11, 2025
PHP min version7.0
Downloads8K

Community Trust

Rating0/100
Number of ratings0
Active installs60
Developer Profile

Sertifier Certificate & Badge Maker for WordPress – Tutor LMS Developer Profile

sertifier

1 plugin · 60 total installs

84
trust score
Avg Security Score
77/100
Avg Patch Time
6 days
View full developer profile
Detection Fingerprints

How We Detect Sertifier Certificate & Badge Maker for WordPress – Tutor LMS

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sertifier-certificates-open-badges/assets/css/style.css/wp-content/plugins/sertifier-certificates-open-badges/assets/js/admin.js
Script Paths
/wp-content/plugins/sertifier-certificates-open-badges/assets/js/admin.js
Version Parameters
sertifier-certificates-open-badges/assets/css/style.css?ver=sertifier-certificates-open-badges/assets/js/admin.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-sertifier-emaildata-sertifier-token
JS Globals
plugin_ajax_object
REST Endpoints
/wp-json/sertifier/v1/get_settings/wp-json/sertifier/v1/save_settings/wp-json/sertifier/v1/get_issues/wp-json/sertifier/v1/add_issue/wp-json/sertifier/v1/delete_issue
Shortcode Output
[sertifier_display_certificate][sertifier_display_badge]
FAQ

Frequently Asked Questions about Sertifier Certificate & Badge Maker for WordPress – Tutor LMS