
Vandar.io learnpress Security & Risk Analysis
wordpress.org/plugins/vandar-learnpressپرداخت اینترنتی وجه به وسیله درگاه پرداخت واسط وندار
Is Vandar.io learnpress Safe to Use in 2026?
Generally Safe
Score 85/100Vandar.io learnpress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The vandar-learnpress plugin v2.1.3 exhibits a strong security posture based on the provided static analysis. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, which significantly limits the plugin's attack surface. Furthermore, the analysis reveals a complete absence of dangerous functions and SQL queries that do not utilize prepared statements, indicating good coding practices in these critical areas. The plugin also shows a high percentage of properly escaped output, which is crucial for preventing cross-site scripting (XSS) vulnerabilities.
However, the analysis does highlight a couple of areas for concern. Specifically, there are two identified flows with unsanitized paths. While the taint analysis did not flag these as critical or high severity, unsanitized paths can still lead to various security issues depending on how they are handled. Additionally, the plugin has zero nonce checks and zero capability checks. This is a significant weakness, especially for functionalities that might involve sensitive operations. The lack of vulnerability history is a positive sign, suggesting the plugin has historically been secure or has had its past issues promptly addressed, but it doesn't negate the current identified risks.
In conclusion, the plugin demonstrates good foundational security by avoiding common pitfalls like raw SQL and dangerous functions. The low attack surface is also a major strength. Nevertheless, the identified unsanitized paths and the complete absence of nonce and capability checks represent tangible security risks that should be addressed to further strengthen the plugin's security.
Key Concerns
- Zero nonce checks found
- Zero capability checks found
- Flows with unsanitized paths found
Vandar.io learnpress Security Vulnerabilities
Vandar.io learnpress Code Analysis
Output Escaping
Data Flow Analysis
Vandar.io learnpress Attack Surface
WordPress Hooks 7
Maintenance & Trust
Vandar.io learnpress Maintenance & Trust
Maintenance Signals
Community Trust
Vandar.io learnpress Alternatives
Thim Kit for Elementor – Pre-built Templates & Widgets for Elementor
thim-elementor-kit
Thim Elementor Kit is a plugin which supports users to build theme, layout, page, post, product, Woocommerce, LearnPress, courses with Elementor.
All-in-One Addons for Elementor – WidgetKit
widgetkit-for-elementor
Build stunning websites with Elementor using premium widgets for WooCommerce, LearnDash & LearnPress. Free creative, content & dynamic widget pack.
LearnPress – Backup & Migration Tool
learnpress-import-export
LearnPress Export/Import bring you feature to export course, lesson, quiz, question from a LearnPress site to back up or bring to another LearnPress s …
Cool Integration for LearnPress & WooCommerce
manca-lp-wc-integration
Lite plugin to get LearnPress Courses & WooCommerce Product on Sync. User Auto Enrollment on Payment Complete.
Visibility Control for LearnPress
visibility-control-for-learnpress
Visibility Control for LearnPress helps you hide messages and content for specific criterion anywhere on your WordPress page.
Vandar.io learnpress Developer Profile
4 plugins · 120 total installs
How We Detect Vandar.io learnpress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/vandar-learnpress/assets/images/vandar.pngHTML / DOM Fingerprints
data-lp-gateway='vandar'/wp-json/learn-press/v1/payment-gateways/vandar