LiveComm Tutorshop Security & Risk Analysis

wordpress.org/plugins/tutorshop

Plugin that brings the physical shopping experience to the online world. You interact in real time with your customers via live and chat, and sell you …

0 active installs v0.0.1 PHP 7.0+ WP 5.7+ Updated Jun 19, 2022
livecommerceshopstreamingvideowoocomerceyoutube
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is LiveComm Tutorshop Safe to Use in 2026?

Generally Safe

Score 85/100

LiveComm Tutorshop has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The 'tutorshop' v0.0.1 plugin presents a mixed security posture. On the positive side, it shows no recorded vulnerabilities (CVEs) and avoids dangerous functions, direct SQL queries, file operations, and external HTTP requests. The use of prepared statements for its SQL queries (though none were found in the analysis) and the presence of capability checks are good practices. However, significant concerns arise from the static analysis. The plugin exposes two REST API routes without any permission callbacks, creating a direct attack vector. Furthermore, it lacks nonce checks on its AJAX handlers, which are also unprotected. This absence of robust authentication and authorization for critical entry points is a serious weakness, potentially allowing unauthorized actions. The high percentage of properly escaped output (71%) is a strength, but the remaining 29% could still be a source of XSS vulnerabilities if exploitable data flows are present. The lack of taint analysis results, while indicating no *detected* critical or high-severity flows, might be due to the limited scope of the analysis rather than an absolute guarantee of safety.

Key Concerns

  • REST API routes without permission callbacks
  • Unprotected AJAX handlers (no auth checks)
  • Missing nonce checks on AJAX
  • Unescaped output (29% of total)
Vulnerabilities
None known

LiveComm Tutorshop Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

LiveComm Tutorshop Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
17 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

71% escaped24 total outputs
Attack Surface
2 unprotected

LiveComm Tutorshop Attack Surface

Entry Points4
Unprotected2

REST API Routes 2

GET/wp-json/tutorshop/v1/getCurrentLiveincludes\class-tutorshop.php:57
GET/wp-json/tutorshop/v1/getCurrentShortCodeincludes\class-tutorshop.php:65

Shortcodes 2

[tutorshop] includes\class-tutorshop-shortcode.php:9
[playerScriptFront] includes\class-tutorshop-shortcode.php:10
WordPress Hooks 10
actionadmin_menuincludes\class-tutorshop-admin.php:19
actionadmin_initincludes\class-tutorshop-admin.php:20
actionadmin_footer_textincludes\class-tutorshop-admin.php:22
actionadmin_noticesincludes\class-tutorshop-admin.php:23
actionadmin_enqueue_scriptsincludes\class-tutorshop-admin.php:25
actionrest_api_initincludes\class-tutorshop.php:56
actionrest_api_initincludes\class-tutorshop.php:64
actionadmin_noticestutorshop.php:49
actioninittutorshop.php:160
actionplugins_loadedtutorshop.php:163
Maintenance & Trust

LiveComm Tutorshop Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedJun 19, 2022
PHP min version7.0
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

LiveComm Tutorshop Developer Profile

Tutorshop Live Commerce

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect LiveComm Tutorshop

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tutorshop/includes/js/tutorshop-admin-frontend.js
Script Paths
/wp-content/plugins/tutorshop/includes/js/tutorshop-admin-frontend.js
Version Parameters
tutorshop/style.css?ver=tutorshop/js/tutorshop-admin-frontend.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-tutorshop
JS Globals
tutorshop_admin_frontend
FAQ

Frequently Asked Questions about LiveComm Tutorshop