Tutor LMS BunnyNet Integration Security & Risk Analysis

wordpress.org/plugins/tutor-lms-bunnynet-integration

Host your videos on BunnyNet bufferless high-speed streaming platform, and facilitate the videos to your students on your LMS platform powered by Tuto …

1K active installs v1.0.1 PHP 7.4+ WP 5.3+ Updated Mar 9, 2026
bunnynetlmsstreamingtutorvideo
78
B · Generally Safe
CVEs total1
Unpatched1
Last CVEJan 19, 2026
Safety Verdict

Is Tutor LMS BunnyNet Integration Safe to Use in 2026?

Mostly Safe

Score 78/100

Tutor LMS BunnyNet Integration is generally safe to use. 1 past CVE were resolved. Keep it updated.

1 known CVE 1 unpatched Last CVE: Jan 19, 2026Updated 25d ago
Risk Assessment

The static analysis of tutor-lms-bunnynet-integration v1.0.1 reveals a surprisingly clean codebase with no apparent entry points like AJAX handlers, REST API routes, or shortcodes. Furthermore, the code demonstrates good practices by avoiding dangerous functions, all SQL queries utilize prepared statements, and all output is properly escaped. There are no file operations or external HTTP requests detected, and importantly, no nonce or capability checks were found, which could be an area of concern if any entry points were present. Taint analysis also indicates no unsanitized paths, suggesting no immediate risks of data injection or manipulation originating from the analyzed code itself.

However, the plugin's vulnerability history presents a significant concern. It has a known unpatched medium severity CVE related to Cross-Site Scripting (XSS). The presence of a past vulnerability, especially one that remains unpatched and is of medium severity, indicates potential weaknesses in the plugin's development or maintenance lifecycle. The fact that the last vulnerability was reported in 2026 suggests a potential future issue that has been disclosed but not yet addressed by the developer. While the current code analysis is promising, the historical data strongly suggests that this plugin should be approached with caution until the known CVE is resolved.

Key Concerns

  • Unpatched CVE (Medium Severity)
Vulnerabilities
1

Tutor LMS BunnyNet Integration Security Vulnerabilities

CVEs by Year

1 CVE in 2026 · unpatched
2026
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2026-24584medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Tutor LMS BunnyNet Integration <= 1.0.0 - Authenticated (Tutor instructor+) Stored Cross-Site Scripting

Jan 19, 2026Unpatched
Code Analysis
Analyzed Mar 16, 2026

Tutor LMS BunnyNet Integration Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
11 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped11 total outputs
Attack Surface

Tutor LMS BunnyNet Integration Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionadmin_noticesincludes\AdminNotice\AdminNotice.php:34
filtertutor_preferred_video_sourcesincludes\Integration\BunnyNet.php:32
filtertutor_single_lesson_videoincludes\Integration\BunnyNet.php:33
filtertutor_course/single/videoincludes\Integration\BunnyNet.php:34
actiontutor_after_video_meta_box_itemincludes\Integration\BunnyNet.php:35
filtershould_tutor_load_templateincludes\Integration\BunnyNet.php:36
actiontutor_after_video_source_iconincludes\Integration\BunnyNet.php:37
actionplugins_loadedtutor-lms-bunnynet-integration.php:57
actioninittutor-lms-bunnynet-integration.php:58
Maintenance & Trust

Tutor LMS BunnyNet Integration Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 9, 2026
PHP min version7.4
Downloads6K

Community Trust

Rating100/100
Number of ratings2
Active installs1K
Developer Profile

Tutor LMS BunnyNet Integration Developer Profile

Themeum

14 plugins · 675K total installs

70
trust score
Avg Security Score
87/100
Avg Patch Time
269 days
View full developer profile
Detection Fingerprints

How We Detect Tutor LMS BunnyNet Integration

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tutor-lms-bunnynet-integration/assets/css/tutor-lms-bunnynet-integration.css/wp-content/plugins/tutor-lms-bunnynet-integration/assets/js/tutor-lms-bunnynet-integration.js
Script Paths
/wp-content/plugins/tutor-lms-bunnynet-integration/assets/js/tutor-lms-bunnynet-integration.js
Version Parameters
tutor-lms-bunnynet-integration/assets/css/tutor-lms-bunnynet-integration.css?ver=tutor-lms-bunnynet-integration/assets/js/tutor-lms-bunnynet-integration.js?ver=

HTML / DOM Fingerprints

CSS Classes
video_source_wrap_bunnynet
Data Attributes
value="<?php esc_htmlplaceholder="<?php esc_html
FAQ

Frequently Asked Questions about Tutor LMS BunnyNet Integration