The School Management System is a WordPress plugin to manage school and its entities such as classes, sections, students, ID cards, teachers, staff, f …
| Code | Message | Location | Category | |
|---|---|---|---|---|
| ERROR | WordPress.DB.PreparedSQL.NotPrepared | Use placeholders and $wpdb->prepare(); found WLSM_CLASS_SCHOOL | 293:14 | Security |
| ERROR | WordPress.DB.PreparedSQL.NotPrepared | Use placeholders and $wpdb->prepare(); found WLSM_CLASSES | 294:14 | Security |
| ERROR | WordPress.DB.PreparedSQL.NotPrepared | Use placeholders and $wpdb->prepare(); found WLSM_INVOICES | 295:25 | Security |
| ERROR | WordPress.WP.I18n.TextDomainMismatch | Mismatched text domain. Expected 'school-management-system' but got 'school-management'. | 127:163 | General |
| ERROR | WordPress.DB.PreparedSQL.NotPrepared | Use placeholders and $wpdb->prepare(); found WLSM_SETTINGS | 286:82 | Security |
| ERROR | WordPress.DB.PreparedSQL.NotPrepared | Use placeholders and $wpdb->prepare(); found WLSM_PAYMENTS | 304:93 | Security |
| ERROR | WordPress.DB.PreparedSQL.NotPrepared | Use placeholders and $wpdb->prepare(); found WLSM_SCHOOLS | 305:12 | Security |
| ERROR | PluginCheck.Security.DirectDB.UnescapedDBParameter | Unescaped parameter $rows_query used in $wpdb->get_var($rows_query)\n$rows_query assigned unsafely at line 178:\n $rows_query = WLSM_M_Staff_Class::fetch_sections_query_count($school_id, $class_school_id)\n$school_id assigned unsafely at line 122:\n $school_id = $current_user['school']['id']\n$current_user['school']['id'] used without escaping. | 181:30 | Security |
| ERROR | WordPress.DB.PreparedSQL.NotPrepared | Use placeholders and $wpdb->prepare(); found $rows_query | 181:38 | Security |
| ERROR | PluginCheck.Security.DirectDB.UnescapedDBParameter | Unescaped parameter $rows_query used in $wpdb->get_var($rows_query . ' AND (' . $condition . ')')\n$rows_query assigned unsafely at line 178:\n $rows_query = WLSM_M_Staff_Class::fetch_sections_query_count($school_id, $class_school_id)\n$school_id assigned unsafely at line 122:\n $school_id = $current_user['school']['id']\n$current_user['school']['id'] used without escaping. | 185:32 | Security |
| 15.11.2025, 10:28:43 | 48s | 1 | 1699 | 2146 |