
WPComplete Security & Risk Analysis
wordpress.org/plugins/wpcompleteA WordPress plugin that helps your students keep track of their progress through your course.
Is WPComplete Safe to Use in 2026?
Generally Safe
Score 95/100WPComplete has a strong security track record. Known vulnerabilities have been patched promptly.
The wpcomplete v2.9.5.4 plugin exhibits a mixed security posture. While it demonstrates strong practices in SQL query handling and avoids dangerous functions and file operations, several areas present significant concerns. The static analysis highlights 17 unprotected AJAX handlers, which represent a substantial attack surface that could be exploited without proper authentication. Additionally, the taint analysis indicates 6 flows with unsanitized paths, though thankfully none reached critical or high severity in this analysis. The plugin's vulnerability history is a notable weakness, with 4 known medium severity CVEs, primarily related to missing authorization and Cross-Site Scripting. The fact that the last vulnerability was so recent (2025-10-24) suggests a recurring pattern of security issues that, while currently patched, points to potential systemic weaknesses in input validation and authorization enforcement. Overall, the plugin has strengths in its code execution and data handling but requires attention to its exposed AJAX endpoints and the historical pattern of security flaws.
Key Concerns
- 17 unprotected AJAX handlers
- 6 flows with unsanitized paths
- 4 medium severity CVEs in history
- 57% output properly escaped
WPComplete Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
WPComplete <= 2.9.5.3 - Missing Authorization
WPComplete <= 2.9.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
WPComplete <= 2.9.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
WPComplete <= 2.9.4 - Reflected Cross-Site Scripting
WPComplete Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WPComplete Attack Surface
AJAX Handlers 17
Shortcodes 52
WordPress Hooks 65
Maintenance & Trust
WPComplete Maintenance & Trust
Maintenance Signals
Community Trust
WPComplete Alternatives
Semrush SEO Writing Assistant
semrush-seo-writing-assistant
The Semrush SEO Writing Assistant provides instant recommendations for content optimization based on the best-performing articles in Google's top 10.
Email Marketing Plugin – WP Email Capture
wp-email-capture
Double opt-in form for building your email list. Define landing pages to distribute your ebooks & software.
WP eBay Product Feeds
ebay-feeds-for-wordpress
Display feeds of eBay Products from eBay Partner Network on your site.
Inline Tweet Sharer – Twitter Sharing Plugin
inline-tweet-sharer
Inline Tweet Sharer is a plugin that allows you to easily and simply create links to share your content on twitter. These links share whatever the anc …
Manual Completions TutorLMS
manual-completions-tutorlms
Manual Completions for Tutor LMS lets you check completion as well as manually mark courses, lessons and quizzes as complete.
WPComplete Developer Profile
26 plugins · 3.1M total installs
How We Detect WPComplete
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpcomplete/css/wpcomplete-admin.css/wp-content/plugins/wpcomplete/js/wpcomplete-admin.js/wp-content/plugins/wpcomplete/js/wpcomplete-admin.jswpcomplete/css/wpcomplete-admin.css?ver=wpcomplete/js/wpcomplete-admin.js?ver=HTML / DOM Fingerprints
wpcomplete-course-statistics<!-- WPComplete Course Statistics -->data-wpcomplete-idWPCOMPLETE_PRODUCT_NAME