ConvertKit Addon for WP Courseware Security & Risk Analysis

wordpress.org/plugins/wp-courseware-convertkit-addon

Subscribe your customers to ConvertKit forms, sequences, and tags upon enrollment complete with webhooks.

10 active installs v1.0.0 PHP 5.6.2+ WP 4.8.0+ Updated Nov 19, 2024
convertkitlearning-management-systemwordpress-lms
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ConvertKit Addon for WP Courseware Safe to Use in 2026?

Generally Safe

Score 92/100

ConvertKit Addon for WP Courseware has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "wp-courseware-convertkit-addon" v1.0.0 exhibits a generally good security posture based on the provided static analysis and vulnerability history. The absence of dangerous functions, the use of prepared statements for all SQL queries, and 100% output escaping are strong indicators of secure coding practices. Furthermore, the plugin has no recorded vulnerabilities, suggesting a history of responsible development and maintenance. The limited attack surface with zero unprotected entry points is also a significant strength.

However, a notable concern is the complete absence of nonce checks. While the plugin has a capability check, the lack of nonces on any potential entry points (even though currently none are exposed) leaves it vulnerable to Cross-Site Request Forgery (CSRF) attacks should new AJAX handlers, shortcodes, or other interactive elements be introduced in future versions without proper security implementation. The presence of file operations and external HTTP requests, while not inherently insecure, are areas that warrant careful monitoring for potential vulnerabilities in future audits or if any issues arise.

Overall, this version of the plugin appears secure with no immediate critical or high risks identified. The strengths in SQL and output handling are commendable. The primary area for improvement lies in the consistent implementation of nonce checks to protect against CSRF, especially considering the potential for future expansion of the plugin's functionality.

Key Concerns

  • Missing nonce checks on all entry points
Vulnerabilities
None known

ConvertKit Addon for WP Courseware Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

ConvertKit Addon for WP Courseware Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
47 escaped
Nonce Checks
0
Capability Checks
1
File Operations
2
External Requests
8
Bundled Libraries
0

Output Escaping

100% escaped47 total outputs
Attack Surface

ConvertKit Addon for WP Courseware Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 20
filterwpcw_api_endointsincludes\api.php:21
filterwpcw_course_tabsincludes\course.php:21
actionwpcw_fields_field_convertkitselectincludes\course.php:22
actionwpcw_fields_field_convertkitselect_viewsincludes\course.php:23
filterwpcw_fields_validate_field_convertkitselectincludes\course.php:24
actionwpcw_fields_field_convertkitwebhooksincludes\course.php:25
actionwpcw_fields_field_convertkitwebhooks_viewsincludes\course.php:26
actionwpcw_enqueue_scriptsincludes\course.php:27
actionwpcw_enroll_userincludes\enrollment.php:17
actionadmin_noticesincludes\requirements.php:30
actionadmin_noticesincludes\requirements.php:36
actionadmin_noticesincludes\requirements.php:42
actionadmin_noticesincludes\requirements.php:48
actionadmin_initincludes\requirements.php:53
filterwpcw_admin_settings_tab_addonsincludes\settings.php:19
actionwpcw_enqueue_scriptsincludes\settings.php:20
actionwpcw_api_convertkitincludes\webhooks.php:17
filterwpcw_registration_generate_usernameincludes\webhooks.php:244
filterwpcw_registration_generate_passwordincludes\webhooks.php:245
actionplugins_loadedwpcw-convertkit.php:52
Maintenance & Trust

ConvertKit Addon for WP Courseware Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedNov 19, 2024
PHP min version5.6.2
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

ConvertKit Addon for WP Courseware Developer Profile

flyplugins

16 plugins · 2K total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ConvertKit Addon for WP Courseware

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-courseware-convertkit-addon/assets/css/wpcw-convertkit-admin.css/wp-content/plugins/wp-courseware-convertkit-addon/assets/js/wpcw-convertkit-admin.js/wp-content/plugins/wp-courseware-convertkit-addon/assets/js/wpcw-convertkit-frontend.js
Script Paths
/wp-content/plugins/wp-courseware-convertkit-addon/assets/js/wpcw-convertkit-admin.js/wp-content/plugins/wp-courseware-convertkit-addon/assets/js/wpcw-convertkit-frontend.js
Version Parameters
wp-courseware-convertkit-addon/assets/css/wpcw-convertkit-admin.css?ver=wp-courseware-convertkit-addon/assets/js/wpcw-convertkit-admin.js?ver=wp-courseware-convertkit-addon/assets/js/wpcw-convertkit-frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
wpcw-field-convertkitselect-wrapperwpcw-field-convertkitselect-dropdown
Data Attributes
data-placeholderwpcw-field-convertkitselect
FAQ

Frequently Asked Questions about ConvertKit Addon for WP Courseware