
UpSells For LearnDash Security & Risk Analysis
wordpress.org/plugins/upsells-for-learndashUpSells for LearnDash allows you to create a widget on LearnDash course page that enables you to display other related courses of your choice.
Is UpSells For LearnDash Safe to Use in 2026?
Generally Safe
Score 100/100UpSells For LearnDash has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The upsells-for-learndash plugin, version 1.1.3, exhibits a generally strong security posture based on the static analysis. The absence of critical findings in taint analysis, coupled with 100% proper output escaping and prepared statement usage for SQL queries, suggests good development practices and a low risk of common web vulnerabilities like SQL injection and cross-site scripting. The presence of nonce checks on all identified AJAX entry points further bolsters its security.
However, a notable area of concern is the complete lack of capability checks on the two identified AJAX handlers. While nonce checks prevent basic CSRF attacks, the absence of capability checks means that any authenticated user, regardless of their role or permissions, could potentially trigger these AJAX actions. This could lead to unintended functionality execution if these handlers perform sensitive operations. The vulnerability history being completely clear is a positive indicator, suggesting a consistent track record of security, but it doesn't negate the potential risks identified in the code itself.
In conclusion, the plugin appears to be well-developed with respect to common vulnerabilities like XSS and SQL injection. The primary weakness lies in the insufficient authorization checks for its AJAX handlers, which represents a potential privilege escalation or unintended action risk. While the attack surface is small and otherwise protected, this oversight warrants attention.
Key Concerns
- AJAX handlers missing capability checks
UpSells For LearnDash Security Vulnerabilities
UpSells For LearnDash Release Timeline
UpSells For LearnDash Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
UpSells For LearnDash Attack Surface
AJAX Handlers 2
WordPress Hooks 15
Maintenance & Trust
UpSells For LearnDash Maintenance & Trust
Maintenance Signals
Community Trust
UpSells For LearnDash Alternatives
Frequently Bought Together for LearnDash
saffire-frequently-bought-together-learndash
Frequently Bought Together for LearnDash is a plugin that allows you to display a section that shows courses most usually bought together with the cou …
WowRevenue – Product Bundles & Bulk Discounts
revenue
WowRevenue is a combination of product bundles and discount campaigns, including bulk discounts, buy x get y discounts, and more.
Teachable
teachable
Effortlessly connect your Teachable products to WordPress with the official Teachable Buy Button Plugin.
FunnelKit – Funnel Builder for WooCommerce Checkout
funnel-builder
Create high-converting WooCommerce checkout pages, WooCommerce thank you pages & sales funnels with the highest-rated WordPress funnel builder.
WPC Product Bundles for WooCommerce
woo-product-bundle
WPC Product Bundles is a plugin that helps you bundle a few products, offer them at a discount, and watch the sales go up!
UpSells For LearnDash Developer Profile
8 plugins · 860 total installs
How We Detect UpSells For LearnDash
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/upsells-for-learndash/assets/css/ldups-upsells-courses.css/wp-content/plugins/upsells-for-learndash/assets/css/select2.min.css/wp-content/plugins/upsells-for-learndash/assets/css/slick.min.css/wp-content/plugins/upsells-for-learndash/assets/css/font-awesome.min.css/wp-content/plugins/upsells-for-learndash/assets/js/ldups-upsells-courses.js/wp-content/plugins/upsells-for-learndash/assets/js/slick.min.js/wp-content/plugins/upsells-for-learndash/assets/js/sweetalert2.all.min.js/wp-content/plugins/upsells-for-learndash/assets/js/custom-script.js+3 morehttps://www.saffiretech.com/upsells-for-learndash/?utm_source=wp_plugin&utm_medium=plugins_archive&utm_campaign=free2pro&utm_id=c1&utm_term=upgrade_now&utm_content=ldupsupsells-for-learndash/assets/css/ldups-upsells-courses.css?ver=upsells-for-learndash/assets/css/select2.min.css?ver=upsells-for-learndash/assets/css/slick.min.css?ver=upsells-for-learndash/assets/css/font-awesome.min.css?ver=upsells-for-learndash/assets/js/ldups-upsells-courses.js?ver=upsells-for-learndash/assets/js/slick.min.js?ver=upsells-for-learndash/assets/js/sweetalert2.all.min.js?ver=upsells-for-learndash/assets/js/custom-script.js?ver=upsells-for-learndash/assets/css/sweetalert2.min.css?ver=upsells-for-learndash/assets/js/select2.min.js?ver=upsells-for-learndash/assets/js/ldups-backend.js?ver=HTML / DOM Fingerprints
ldups-upsells-coursesldups-upsells-course-wrapldups-upsells-single-courseldups-upsells-course-image-wrapldups-upsells-course-content-wrapldups-upsells-course-titleldups-upsells-course-priceldups-upsells-course-author+23 more<!-- Free to Pro Upgrade alert translation --><!-- metabox display --><!-- upsell widget display --><!-- upsell metabox display -->+2 moredata-ldups-course-iddata-ldups-upsell-idldups_data