
LiveComm Tutorshop Security & Risk Analysis
wordpress.org/plugins/tutorshopPlugin that brings the physical shopping experience to the online world. You interact in real time with your customers via live and chat, and sell you …
Is LiveComm Tutorshop Safe to Use in 2026?
Generally Safe
Score 85/100LiveComm Tutorshop has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'tutorshop' v0.0.1 plugin presents a mixed security posture. On the positive side, it shows no recorded vulnerabilities (CVEs) and avoids dangerous functions, direct SQL queries, file operations, and external HTTP requests. The use of prepared statements for its SQL queries (though none were found in the analysis) and the presence of capability checks are good practices. However, significant concerns arise from the static analysis. The plugin exposes two REST API routes without any permission callbacks, creating a direct attack vector. Furthermore, it lacks nonce checks on its AJAX handlers, which are also unprotected. This absence of robust authentication and authorization for critical entry points is a serious weakness, potentially allowing unauthorized actions. The high percentage of properly escaped output (71%) is a strength, but the remaining 29% could still be a source of XSS vulnerabilities if exploitable data flows are present. The lack of taint analysis results, while indicating no *detected* critical or high-severity flows, might be due to the limited scope of the analysis rather than an absolute guarantee of safety.
Key Concerns
- REST API routes without permission callbacks
- Unprotected AJAX handlers (no auth checks)
- Missing nonce checks on AJAX
- Unescaped output (29% of total)
LiveComm Tutorshop Security Vulnerabilities
LiveComm Tutorshop Code Analysis
Output Escaping
LiveComm Tutorshop Attack Surface
REST API Routes 2
Shortcodes 2
WordPress Hooks 10
Maintenance & Trust
LiveComm Tutorshop Maintenance & Trust
Maintenance Signals
Community Trust
LiveComm Tutorshop Alternatives
The Ultimate Video Player For WordPress – by Presto Player
presto-player
The Ultimate WordPress Video Player.
Advanced WordPress Backgrounds
advanced-backgrounds
Easy to use advanced Parallax, Image and Video backgrounds block plugin with parallax and video support.
WP YouTube Lyte
wp-youtube-lyte
High performance YouTube video, playlist and audio-only embeds which don't slow down your blog and offer optimal accessibility.
All-in-One Video Gallery
all-in-one-video-gallery
The ultimate video player & video gallery plugin for YouTubers, Video Bloggers, Course Creators, Podcasters, and anyone embedding videos on websites.
Video PopUp
video-popup
The ultimate Video Popup plugin for WordPress. Create unlimited and responsive popups for YouTube, Vimeo, MP4 & WebM videos on click or On-Page Load.
LiveComm Tutorshop Developer Profile
1 plugin · 0 total installs
How We Detect LiveComm Tutorshop
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tutorshop/includes/js/tutorshop-admin-frontend.js/wp-content/plugins/tutorshop/includes/js/tutorshop-admin-frontend.jstutorshop/style.css?ver=tutorshop/js/tutorshop-admin-frontend.js?ver=HTML / DOM Fingerprints
data-tutorshoptutorshop_admin_frontend