TutorMate Security & Risk Analysis

wordpress.org/plugins/tutormate

TutorMate is a Tutor Starter theme companion plugin to import predesigned stylish demo pages to eLearning sites powered by Tutor LMS plugin.

10K active installs v3.0.1 PHP 7.0+ WP 5.3+ Updated May 9, 2025
contentdatademoimport
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is TutorMate Safe to Use in 2026?

Generally Safe

Score 100/100

TutorMate has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10mo ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the tutormate plugin v3.0.1 exhibits a strong security posture with no immediate critical vulnerabilities identified. The absence of dangerous functions, SQL injection risks due to prepared statements, and properly escaped output are all positive indicators of good development practices. Furthermore, the plugin's attack surface appears minimal, with no discovered AJAX handlers, REST API routes, shortcodes, or cron events, and crucially, none of these are reported as unprotected.

The lack of any recorded CVEs, historical vulnerabilities, or taint analysis findings further bolsters the perception of a secure plugin. This suggests a proactive approach to security by the developers or a lack of exploitable vulnerabilities discovered to date. The plugin does not appear to perform file operations or external HTTP requests, further reducing potential attack vectors. While the lack of nonce and capability checks on entry points is noted, the absence of any entry points makes this a theoretical concern rather than an immediate risk based on the provided data.

In conclusion, tutormate v3.0.1 appears to be a robustly developed plugin from a security perspective, with a clean bill of health in both static analysis and historical vulnerability data. The developers have implemented secure coding practices regarding database interactions and output handling. The limited attack surface is a significant strength. The primary area for potential future scrutiny, if entry points were to be added, would be the implementation of proper authentication and authorization mechanisms.

Vulnerabilities
None known

TutorMate Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

TutorMate Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped1 total outputs
Attack Surface

TutorMate Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
filterocdi/plugin_page_setupinc\DemoImporter.php:21
filterocdi/import_filesinc\DemoImporter.php:22
filterocdi/register_pluginsinc\DemoImporter.php:23
actionocdi/after_importinc\DemoImporter.php:24
actiontgmpa_registerinc\DemoImporter.php:25
actionadmin_noticestutormate.php:40
actionadmin_inittutormate.php:89
Maintenance & Trust

TutorMate Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedMay 9, 2025
PHP min version7.0
Downloads179K

Community Trust

Rating100/100
Number of ratings1
Active installs10K
Developer Profile

TutorMate Developer Profile

Themeum

14 plugins · 675K total installs

70
trust score
Avg Security Score
87/100
Avg Patch Time
269 days
View full developer profile
Detection Fingerprints

How We Detect TutorMate

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tutormate/assets/css/style.css
Version Parameters
tutormate/assets/css/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
tm-demo-import-wrappertm-demo-site-itemtm-demo-site-item-thumbtm-demo-site-item-content
HTML Comments
<!-- Demo Importer Start --><!-- Demo Importer End --><!-- This section of code is for the Elementor Demo Importer. It is used to register the demo import pages and files. -->
Data Attributes
data-menu-slug="tutormate-demo-import"data-parent-slug="tutorstarter"
FAQ

Frequently Asked Questions about TutorMate