
YaqeenTech Training Operations for Tutor LMS Security & Risk Analysis
wordpress.org/plugins/yaqeentech-training-operations-for-tutor-lmsOperational management layer for Tutor LMS: training plans, bulk enrollment, enrollment batches, and a training calendar.
Is YaqeenTech Training Operations for Tutor LMS Safe to Use in 2026?
Generally Safe
Score 100/100YaqeenTech Training Operations for Tutor LMS has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'yaqeentech-training-operations-for-tutor-lms' version 1.0.26 exhibits a generally good security posture with strong adherence to secure coding practices. The plugin demonstrates excellent use of prepared statements for all SQL queries, a high percentage of properly escaped output, and a robust number of nonce and capability checks, indicating a conscious effort to protect against common web vulnerabilities. Furthermore, the absence of known CVEs and recorded vulnerabilities suggests a history of stable and secure development.
However, a significant concern arises from the presence of one AJAX handler without authentication checks. This creates an exposed entry point that could be exploited if it handles user-supplied data without proper validation and sanitization. While the taint analysis did not reveal critical or high severity issues, the three identified flows with unsanitized paths, even if of lower severity, warrant attention, especially in conjunction with the unprotected AJAX endpoint. The total attack surface is relatively small, but the single unprotected entry point is a notable weakness.
In conclusion, the plugin is built on a solid foundation of secure coding. The comprehensive use of prepared statements and output escaping are significant strengths. The primary weakness lies in the single unprotected AJAX handler, which introduces a potential risk of unauthorized actions or information disclosure. Addressing this single unprotected entry point and further investigating the identified unsanitized paths would significantly bolster the plugin's security.
Key Concerns
- AJAX handler without authentication check
YaqeenTech Training Operations for Tutor LMS Security Vulnerabilities
YaqeenTech Training Operations for Tutor LMS Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
YaqeenTech Training Operations for Tutor LMS Attack Surface
AJAX Handlers 1
Shortcodes 6
WordPress Hooks 23
Maintenance & Trust
YaqeenTech Training Operations for Tutor LMS Maintenance & Trust
Maintenance Signals
Community Trust
YaqeenTech Training Operations for Tutor LMS Alternatives
Lesson Bookmark for Tutor LMS
lesson-bookmark-tutor-lms
Lesson Bookmark allows you to add lessons in the list of your favorite lessons and to display the favorites with [tllb_display_favorites]
Reviews for Tutor LMS
reviews-tutor-lms
The Reviews for Tutor LMS plugin is an addon for Tutor LMS that allows you to manage course reviews.
Custom User Registration Fields for Tutor LMS
custom-user-registration-fields-tutor-lms
Add Custom User Registration Fields for Tutor LMS.
Experience API for TutorLMS by GrassBlade
grassblade-xapi-tutorlms
Experience API for TutorLMS plugin adds xAPI, SCORM, and cmi5 support to Tutor LMS by integrating with the GrassBlade xAPI Companion plugin.
Tutor LMS Author Ownership Changer – Migrate your Course Author Ownership
tutor-lms-author
Easily change the Tutor LMS course author ownership.
YaqeenTech Training Operations for Tutor LMS Developer Profile
1 plugin · 0 total installs
How We Detect YaqeenTech Training Operations for Tutor LMS
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/yaqeentech-training-operations-for-tutor-lms/assets/yaqetrop-trainingflow.css/wp-content/plugins/yaqeentech-training-operations-for-tutor-lms/assets/yaqetrop-trainingflow.js/wp-content/plugins/yaqeentech-training-operations-for-tutor-lms/assets/yaqetrop-trainingflow.jsyaqeentech-training-operations-for-tutor-lms/assets/yaqetrop-trainingflow.css?ver=yaqeentech-training-operations-for-tutor-lms/assets/yaqetrop-trainingflow.js?ver=HTML / DOM Fingerprints
data-yaqetrop-actionyaqetropVars[yaqetrop_calendar][yaqetrop_enrollment_explorer][yaqetrop_enrollment_batches][yaqetrop_bulk_enrollment]