
ConvertKit Addon for WP Courseware Security & Risk Analysis
wordpress.org/plugins/wp-courseware-convertkit-addonSubscribe your customers to ConvertKit forms, sequences, and tags upon enrollment complete with webhooks.
Is ConvertKit Addon for WP Courseware Safe to Use in 2026?
Generally Safe
Score 92/100ConvertKit Addon for WP Courseware has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-courseware-convertkit-addon" v1.0.0 exhibits a generally good security posture based on the provided static analysis and vulnerability history. The absence of dangerous functions, the use of prepared statements for all SQL queries, and 100% output escaping are strong indicators of secure coding practices. Furthermore, the plugin has no recorded vulnerabilities, suggesting a history of responsible development and maintenance. The limited attack surface with zero unprotected entry points is also a significant strength.
However, a notable concern is the complete absence of nonce checks. While the plugin has a capability check, the lack of nonces on any potential entry points (even though currently none are exposed) leaves it vulnerable to Cross-Site Request Forgery (CSRF) attacks should new AJAX handlers, shortcodes, or other interactive elements be introduced in future versions without proper security implementation. The presence of file operations and external HTTP requests, while not inherently insecure, are areas that warrant careful monitoring for potential vulnerabilities in future audits or if any issues arise.
Overall, this version of the plugin appears secure with no immediate critical or high risks identified. The strengths in SQL and output handling are commendable. The primary area for improvement lies in the consistent implementation of nonce checks to protect against CSRF, especially considering the potential for future expansion of the plugin's functionality.
Key Concerns
- Missing nonce checks on all entry points
ConvertKit Addon for WP Courseware Security Vulnerabilities
ConvertKit Addon for WP Courseware Code Analysis
Output Escaping
ConvertKit Addon for WP Courseware Attack Surface
WordPress Hooks 20
Maintenance & Trust
ConvertKit Addon for WP Courseware Maintenance & Trust
Maintenance Signals
Community Trust
ConvertKit Addon for WP Courseware Alternatives
WP Learn Manager
learn-manager
WP Learn Manager is the most comprehensive, extensive, and feature-rich WordPress LMS plugin.
MemberWunder LMS – Learning Management System – Ein WordPress e-Learning Plugin
memberwunder
Ein WordPress e-Learning (LMS) Plugin, um sogenannte WordPress Learning Management Systeme zu erstellen mit anpassbaren Designs und sofort einsetzbare …
WP Courseware – Mailchimp Addon
wp-courseware-mailchimp-addon
Subscribe your customers to MailChimp audience and tags upon enrollment.
Quick Learn
quick-learn
Quick Learn is the best Complete WordPress LMS plugin. It makes simple to create Instructors, Students, Courses, Categories, Tags, lessons, Assessment …
Tutor LMS – eLearning and online course solution
tutor
A complete WordPress LMS plugin to create any eLearning website easily.
ConvertKit Addon for WP Courseware Developer Profile
16 plugins · 2K total installs
How We Detect ConvertKit Addon for WP Courseware
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-courseware-convertkit-addon/assets/css/wpcw-convertkit-admin.css/wp-content/plugins/wp-courseware-convertkit-addon/assets/js/wpcw-convertkit-admin.js/wp-content/plugins/wp-courseware-convertkit-addon/assets/js/wpcw-convertkit-frontend.js/wp-content/plugins/wp-courseware-convertkit-addon/assets/js/wpcw-convertkit-admin.js/wp-content/plugins/wp-courseware-convertkit-addon/assets/js/wpcw-convertkit-frontend.jswp-courseware-convertkit-addon/assets/css/wpcw-convertkit-admin.css?ver=wp-courseware-convertkit-addon/assets/js/wpcw-convertkit-admin.js?ver=wp-courseware-convertkit-addon/assets/js/wpcw-convertkit-frontend.js?ver=HTML / DOM Fingerprints
wpcw-field-convertkitselect-wrapperwpcw-field-convertkitselect-dropdowndata-placeholderwpcw-field-convertkitselect