Vandar.io learnpress Security & Risk Analysis

wordpress.org/plugins/vandar-learnpress

پرداخت اینترنتی وجه به وسیله درگاه پرداخت واسط وندار

0 active installs v2.1.3 PHP + WP 4.5+ Updated Aug 10, 2023
learn-presslearnpress%d9%88%d9%86-%d8%af%d8%a7%d8%b1%d9%88%d9%86%d8%af%d8%a7%d8%b1-%d8%8c-%d9%84%d8%b1%d9%86-%d9%be%d8%b1%d8%b3-%d9%88%d9%86%d8%af%d8%a7%d8%b1-%d8%8c%d9%84%d8%b1%d9%86-%d9%be%d8%b1%d8%b3vandar
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Vandar.io learnpress Safe to Use in 2026?

Generally Safe

Score 85/100

Vandar.io learnpress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The vandar-learnpress plugin v2.1.3 exhibits a strong security posture based on the provided static analysis. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, which significantly limits the plugin's attack surface. Furthermore, the analysis reveals a complete absence of dangerous functions and SQL queries that do not utilize prepared statements, indicating good coding practices in these critical areas. The plugin also shows a high percentage of properly escaped output, which is crucial for preventing cross-site scripting (XSS) vulnerabilities.

However, the analysis does highlight a couple of areas for concern. Specifically, there are two identified flows with unsanitized paths. While the taint analysis did not flag these as critical or high severity, unsanitized paths can still lead to various security issues depending on how they are handled. Additionally, the plugin has zero nonce checks and zero capability checks. This is a significant weakness, especially for functionalities that might involve sensitive operations. The lack of vulnerability history is a positive sign, suggesting the plugin has historically been secure or has had its past issues promptly addressed, but it doesn't negate the current identified risks.

In conclusion, the plugin demonstrates good foundational security by avoiding common pitfalls like raw SQL and dangerous functions. The low attack surface is also a major strength. Nevertheless, the identified unsanitized paths and the complete absence of nonce and capability checks represent tangible security risks that should be addressed to further strengthen the plugin's security.

Key Concerns

  • Zero nonce checks found
  • Zero capability checks found
  • Flows with unsanitized paths found
Vulnerabilities
None known

Vandar.io learnpress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Vandar.io learnpress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
16 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

89% escaped18 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
web_hook_process_vandar (inc\class-lp-gateway-vandar.php:246)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Vandar.io learnpress Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actioninitinc\class-lp-gateway-vandar.php:47
actionlearn_press_web_hooks_processedinc\class-lp-gateway-vandar.php:49
actionlearn-press/before-checkout-order-reviewinc\class-lp-gateway-vandar.php:50
filterlearn_press_payment_methodinc\load.php:28
filterlearn-press/payment-methodsinc\load.php:29
actionlearn-press/readyvandar-learnpress.php:15
actionadmin_noticesvandar-learnpress.php:16
Maintenance & Trust

Vandar.io learnpress Maintenance & Trust

Maintenance Signals

WordPress version tested6.3.0
Last updatedAug 10, 2023
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Vandar.io learnpress Developer Profile

Vandar

4 plugins · 120 total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Vandar.io learnpress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/vandar-learnpress/assets/images/vandar.png

HTML / DOM Fingerprints

Data Attributes
data-lp-gateway='vandar'
REST Endpoints
/wp-json/learn-press/v1/payment-gateways/vandar
FAQ

Frequently Asked Questions about Vandar.io learnpress