WP Courseware for WPBakery Page Builder Security & Risk Analysis

wordpress.org/plugins/vc-addon-for-wp-courseware

This plugin adds integration between WPBakery Page Builder and WP Courseware to customize unit content with WPBakery Page Builder elements.

100 active installs v1.8 PHP + WP 4.8+ Updated Sep 9, 2021
learning-management-systemselling-courses-online
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Courseware for WPBakery Page Builder Safe to Use in 2026?

Generally Safe

Score 85/100

WP Courseware for WPBakery Page Builder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The "vc-addon-for-wp-courseware" v1.8 plugin exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and a clean vulnerability history are significant strengths, suggesting a commitment to security or a lack of exploitation. The code analysis reveals no dangerous functions, all SQL queries are prepared, and output is properly escaped, which are all excellent security practices.

However, a notable concern arises from the limited number of security checks across the identified entry points. While there are few total entry points, the complete absence of nonce checks and capability checks on the single shortcode presents a potential risk. The lack of any taint analysis flows could also indicate that the analysis was not comprehensive or that potential flows were not identified. The absence of any file operations or external HTTP requests reduces the attack surface in those areas. Overall, the plugin has a good foundation but could benefit from more robust security checks on its user-facing components.

Key Concerns

  • Shortcode without nonce check
  • Shortcode without capability check
  • No taint analysis flows found
Vulnerabilities
None known

WP Courseware for WPBakery Page Builder Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP Courseware for WPBakery Page Builder Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

WP Courseware for WPBakery Page Builder Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[wpcourse_unit] visual-composer-addon-for-wp-courseware.php:151
WordPress Hooks 3
actionwp_headvisual-composer-addon-for-wp-courseware.php:24
actionvc_before_initvisual-composer-addon-for-wp-courseware.php:26
filterthe_contentvisual-composer-addon-for-wp-courseware.php:28
Maintenance & Trust

WP Courseware for WPBakery Page Builder Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedSep 9, 2021
PHP min version
Downloads13K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

WP Courseware for WPBakery Page Builder Developer Profile

flyplugins

16 plugins · 2K total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Courseware for WPBakery Page Builder

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/vc-addon-for-wp-courseware/assets/wpcw-icon.png

HTML / DOM Fingerprints

HTML Comments
<!-- Ensure we're only showing a course unit, a single item --><!-- Get associated data for this unit. No course/module data, then it's not a unit --><!-- Check for drip content --><!-- Do not return any content -->+12 more
Shortcode Output
[wpcourse_unit]
FAQ

Frequently Asked Questions about WP Courseware for WPBakery Page Builder