The School Management System is a WordPress plugin to manage school and its entities such as classes, sections, students, ID cards, teachers, staff, f …
| Code | Message | Location | Category | |
|---|---|---|---|---|
| ERROR | WordPress.DB.PreparedSQL.NotPrepared | Use placeholders and $wpdb->prepare(); found WLSM_STUDENT_RECORDS | includes/helpers/staff/WLSM_M_Staff_General.php:143:286 | Security |
| ERROR | WordPress.DB.PreparedSQL.NotPrepared | Use placeholders and $wpdb->prepare(); found WLSM_SESSIONS | includes/helpers/staff/WLSM_M_Staff_General.php:144:12 | Security |
| ERROR | WordPress.DB.PreparedSQL.NotPrepared | Use placeholders and $wpdb->prepare(); found WLSM_SECTIONS | includes/helpers/staff/WLSM_M_Staff_General.php:145:12 | Security |
| ERROR | WordPress.DB.PreparedSQL.NotPrepared | Use placeholders and $wpdb->prepare(); found WLSM_CLASS_SCHOOL | includes/helpers/staff/WLSM_M_Staff_General.php:146:12 | Security |
| ERROR | WordPress.DB.PreparedSQL.NotPrepared | Use placeholders and $wpdb->prepare(); found WLSM_CLASSES | includes/helpers/staff/WLSM_M_Staff_General.php:147:12 | Security |
| ERROR | WordPress.DB.PreparedSQL.NotPrepared | Use placeholders and $wpdb->prepare(); found WLSM_USERS | includes/helpers/staff/WLSM_M_Staff_General.php:148:23 | Security |
| ERROR | WordPress.DateTime.RestrictedFunctions.date_date | date() is affected by runtime timezone changes which can cause date/time to be incorrectly displayed. Use gmdate() instead. | admin/inc/school/staff/general/WLSM_Staff_General.php:1703:34 | — |
| ERROR | WordPress.DB.PreparedSQL.NotPrepared | Use placeholders and $wpdb->prepare(); found WLSM_SETTINGS | includes/helpers/WLSM_M_Setting.php:240:82 | Security |
| ERROR | WordPress.NamingConventions.PrefixAllGlobals.NonPrefixedVariableFound | Global variables defined by a theme/plugin should start with the theme/plugin prefix. Found: "$nonce_action". | admin/inc/manager/settings/index.php:66:29 | Plugin Repo |
| ERROR | PluginCheck.Security.DirectDB.UnescapedDBParameter | Unescaped parameter $query_filter used in $wpdb->get_results($query_filter . $limit)\n$query_filter assigned unsafely at line 1333:\n $query_filter .= ' ORDER BY a.joining_date DESC, a.ID DESC'\n$limit assigned unsafely at line 1337:\n $limit = ''\n$_POST['length'] used without escaping.\n$_POST['start'] used without escaping. | admin/inc/school/staff/general/WLSM_Staff_General.php:1359:31 | Security |
| 12.12.2025, 09:31:08 | 35s | 1 | 1698 | 2141 |
| 15.11.2025, 10:28:43 | 48s | 1 | 1699 | 2146 |