Plugin Pulse
← Pulse

Tutor LMS – eLearning and online course solution

by Themeum · Education

Also makes 12 other plugins · 661.3K+ installs across the portfolio →

A complete WordPress LMS plugin to create any eLearning website easily.

How scoring works →
84 Health · B
Maintenance 100/100
Rating quality 86/100
Support 56/100

84 health vs 66 average across 168 Education plugins

Directory ranking optimization

How it's scored →

How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.

89 / 100

Excellent listing optimization

Biggest win: Support resolution

Update recency 100/100
WP compatibility 100/100
Rating quality 88/100
Listing tuning 100/100
Support resolution 43/100

To rank higher: Mark more forum threads resolved — the resolved ratio feeds the ranking.

Get the full rank-higher report →

Daily downloads

Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive

-18% vs prior 30d
2.3KDownloads · Aug 26

30-day downloads

Rolling 30-day volume · peaks are release surges

148.7K

now · peak 190.5K

147K30d downloads · Aug 26

Directory rank vs rivals

wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you

Tutor LMS · #452 you LearnPress · #598 MasterStudy LMS Word · #1727 StepUp LMS · #47855

Rating trend

Star average over time · dips mark rough releases

4.4Stars · Aug 26

Update activity

How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.

1.5Kper 1k installs · Aug 26

Release cadence

Actively maintained
from wp.org release tags

How often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.

22

releases in the last 12 months

2mo ago

latest release · v4.0.1

184

tagged releases on record

Recent releases

4.0.1 · 2mo ago4.0.0 · 2mo ago3.9.15 · 2mo ago3.9.14 · 2mo ago3.9.13 · 2mo ago3.9.12 · 3mo ago3.9.11 · 3mo ago3.9.10 · 4mo ago3.9.9 · 4mo ago3.9.8 · 5mo ago3.9.7 · 6mo ago3.9.6 · 7mo ago3.9.5 · 8mo ago3.9.4 · 8mo ago

What its installed base runs

via wordpress.org

Share of active installs on each version of this plugin · 26% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.

v3.9 48%
v4.0 26%
Older / other versions 26%

Estimated active installs

The public count shows “100K+”. Our estimate pins where the real number sits.

tracked estimate
100K–200K ≈190K

Refined from the date this plugin crossed into its current band.

Install history · since 2019-07-16 · 1,454 observations

100KInstalls · Aug 26

Estimated value

What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.

Est. annual revenue

N/A

Est. acquisition value

N/A

No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. A declining trend compresses what a buyer would pay.

Details

Version
4.0.7
Last updated
4d ago
Added
2019-02-06 · 7 yrs old
Requires WP
5.3
Tested up to
7.0.4
Requires PHP
7.4

Recent reviews

All reviews on wp.org ↗
  1. guezs
    1mo ago

    Ha cambiado todo. Los menús están en inglés. Las personalizaciones no funcionan. Los usuarios están desconcertados y perdidos.

    Read on wp.org ↗
  2. lazarmld
    2mo ago

    It’s great plugin and all, but this auto-update to 4.0 version and breaking everyones sites is a bold move. And then closing option to open a ticket for a free plugin is even bolder. Well played Tutor.Edit: they have open the support threads, you get one star back This topic was modified 1 week, 2 days ago by lazarmld.

    Read on wp.org ↗
  3. susanbastin
    4mo ago

    Support team is very helpful, especially Mr. Rashed helped me a lot.

    Read on wp.org ↗
  4. lashram
    5mo ago

    Having issues with TutorLMS on my site and the 24/7 support isn’t live, I wanted to work through my issues in real time and their only offer was for me to provide access to my admin. Absolutely not! I don’t trust anyone with admin access unsupervised! Luckily it’s opensource and I have some skills …

    Read on wp.org ↗
  5. karanu123
    7mo ago

    I bought the Tutor Pro app, but had challenges installing the theme. I applaud the support team for guiding me through the entire onboarding process and forsetting up the app and theme on my site. All I have to do is create my courses and edit the theme to my liking. Thank you, the support team.

    Read on wp.org ↗
  6. matteo raggi
    7mo ago

    I tested many lms, dozens and it looks to eb the best to my eyes.

    Read on wp.org ↗
  7. altaira84
    7mo ago

    Sama darmowa wersja działała jako tako choć była bardzo toporna i ograniczona! Nie pozwalała nawet podejrzeć kursu w czasie jego tworzenia! To Żenujące! Prawdziwe problemy zaczęły się po instalacji PRO! Wszyscy klienci stracili historię zamówień kursów a tym samym dostęp do kursów za które zapłacili! Licencja nie działa a gwarantowana obsługa 24/7 ma w dup…e problemy klientów premium i nawet nie raczy udzielić pomocy w tym zakresie! Oczekiwanie na odpowiedź to od kilkunastu godzin do kilku dni! Człowiek zapłacił prawie tysiąc złotych i został sam z problemem! NIE POLECAM!

    Read on wp.org ↗
  8. rosterdotcom
    8mo ago

    Posted many days ago about issues this plugin has and nothing. I’m not the only one. Others have posted with no responses. This plugin has potential but with the lack of support, well, it’s just useless. Do better!

    Read on wp.org ↗

Known vulnerabilities

via Wordfence Intelligence

79 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.

  1. 2026-07-30 CVE-2026-14310 Missing Authorization Affects < 4.0.0 Patched in 4.0.0
  2. 2026-07-27 CVE-2026-15444 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 4.0.1 Patched in 4.0.2
  3. 2026-07-15 CVE-2026-15022 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 4.0.0 Patched in 4.0.1
  4. 2026-07-06 CVE-2026-57694 Authorization Bypass Through User-Controlled Key Affects <= 3.9.13 Patched in 3.9.14
  5. 2026-07-02 CVE-2026-14306 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 3.9.13 Patched in 3.9.14
  6. 2026-06-30 CVE-2026-13443 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.9.13 Patched in 3.9.14
  7. 2026-06-22 CVE-2026-12275 Improper Authentication Affects <= 3.9.12 Patched in 3.9.13
  8. 2026-06-22 CVE-2026-12273 Missing Authorization Affects <= 3.9.12 Patched in 3.9.13
  9. 2026-06-22 CVE-2026-12271 Authorization Bypass Through User-Controlled Key Affects <= 3.9.12 Patched in 3.9.13
  10. 2026-06-17 CVE-2026-10736 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 3.9.11 Patched in 3.9.12
  11. 2026-05-12 CVE-2026-6965 Authorization Bypass Through User-Controlled Key Affects <= 3.9.9 Patched in 3.9.10
  12. 2026-04-20 CVE-2026-40743 Missing Authorization Affects <= 3.9.7 Patched in 3.9.8
  13. 2026-04-16 CVE-2026-6080 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 3.9.8 Patched in 3.9.9
  14. 2026-04-16 CVE-2026-5502 Missing Authorization Affects <= 3.9.8 Patched in 3.9.9
  15. 2026-04-10 CVE-2026-3371 Authorization Bypass Through User-Controlled Key Affects <= 3.9.7 Patched in 3.9.8
  16. 2026-04-10 CVE-2026-3358 Missing Authorization Affects <= 3.9.7 Patched in 3.9.8
  17. 2026-04-09 CVE-2026-3360 Missing Authorization Affects <= 3.9.7 Patched in 3.9.8
  18. 2026-03-16 CVE-2025-32223 Authorization Bypass Through User-Controlled Key Affects <= 3.9.4 Patched in 3.9.5
  19. 2026-03-15 CVE-2026-40740 Missing Authorization Affects <= 3.9.7 Patched in 3.9.8
  20. 2026-02-27 CVE-2025-13673 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 3.9.6 Patched in 3.9.7
  21. 2026-02-25 CVE-2026-23799 Missing Authorization Affects <= 3.9.5 Patched in 3.9.6
  22. 2026-02-02 CVE-2026-1371 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 3.9.5 Patched in 3.9.6
  23. 2026-02-02 CVE-2026-1375 Authorization Bypass Through User-Controlled Key Affects <= 3.9.5 Patched in 3.9.6
  24. 2026-01-20 CVE-2026-0548 Missing Authorization Affects <= 3.9.4 Patched in 3.9.5
  25. 2026-01-08 CVE-2025-13628 Missing Authorization Affects <= 3.9.3 Patched in 3.9.4
  26. 2026-01-08 CVE-2025-13935 Missing Authorization Affects <= 3.9.2 Patched in 3.9.4
  27. 2026-01-08 CVE-2025-13934 Missing Authorization Affects <= 3.9.3 Patched in 3.9.4
  28. 2026-01-07 CVE-2025-13679 Missing Authorization Affects <= 3.9.3 Patched in 3.9.4
  29. 2026-01-02 CVE-2025-47555 Authorization Bypass Through User-Controlled Key Affects <= 3.9.4 Patched in 3.9.5
  30. 2025-10-24 CVE-2025-6680 Improper Access Control Affects <= 3.8.3 Patched in 3.9.0
  31. 2025-10-24 CVE-2025-11564 Missing Authorization Affects <= 3.8.3 Patched in 3.9.0
  32. 2025-09-09 CVE-2025-58993 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 3.7.4 Patched in 3.8.0
  33. 2025-04-07 CVE-2025-32230 Improper Input Validation Affects <= 3.4.0 Patched in 3.4.1
  34. 2024-11-20 CVE-2024-10400 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 2.7.6 Patched in 2.7.7
  35. 2024-11-20 CVE-2024-10393 Improper Access Control Affects <= 2.7.6 Patched in 2.7.7
  36. 2024-09-09 CVE-2023-2919 Cross-Site Request Forgery (CSRF) Affects <= 2.7.4 Patched in 2.7.5
  37. 2024-08-16 CVE-2024-43282 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 2.7.2 Patched in 2.7.3
  38. 2024-08-09 CVE-2024-43231 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.7.3 Patched in 2.7.4
  39. 2024-08-07 CVE-2024-43142 Missing Authorization Affects <= 2.7.3 Patched in 2.7.4
  40. 2024-08-01 CVE-2024-39645 Cross-Site Request Forgery (CSRF) Affects <= 2.7.2 Patched in 2.7.3
  41. 2024-07-10 CVE-2024-37947 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.7.2 Patched in 2.7.3
  42. 2024-06-27 CVE-2024-37266 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 2.7.1 Patched in 2.7.2
  43. 2024-06-06 CVE-2024-4902 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 2.7.1 Patched in 2.7.2
  44. 2024-06-06 CVE-2024-5438 Authorization Bypass Through User-Controlled Key Affects <= 2.7.1 Patched in 2.7.2
  45. 2024-05-15 CVE-2024-4279 Authorization Bypass Through User-Controlled Key Affects <= 2.7.0 Patched in 2.7.1
  46. 2024-05-15 CVE-2024-4318 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 2.7.0 Patched in 2.7.1
  47. 2024-05-15 CVE-2024-4223 Missing Authorization Affects <= 2.7.0 Patched in 2.7.1
  48. 2024-04-26 CVE-2024-3553 Missing Authorization Affects <= 2.6.2 Patched in 2.7.0
  49. 2024-04-24 CVE-2024-3994 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.6.2 Patched in 2.7.0
  50. 2024-03-12 CVE-2024-1503 Cross-Site Request Forgery (CSRF) Affects <= 2.6.1 Patched in 2.6.2
  51. 2024-03-12 CVE-2024-1502 Missing Authorization Affects <= 2.6.1 Patched in 2.6.2
  52. 2024-03-11 CVE-2024-1751 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 2.6.1 Patched in 2.6.2
  53. 2024-02-20 CVE-2024-1128 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Affects <= 2.6.0 Patched in 2.6.1
  54. 2024-02-20 CVE-2024-1133 Missing Authorization Affects <= 2.6.0 Patched in 2.6.1
  55. 2023-12-05 CVE-2023-49829 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.2.4 Patched in 2.3.0
  56. 2023-09-25 CVE-2023-4805 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.2.4 Patched in 2.3.0
  57. 2023-06-12 CVE-2023-3133 Missing Authorization Affects <= 2.2.0 Patched in 2.2.1
  58. 2023-05-30 CVE-2023-25800 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 2.2.0 Patched in 2.2.1
  59. 2023-05-30 CVE-2023-25990 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 2.1.10 Patched in 2.2.0
  60. 2023-05-30 CVE-2023-25700 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 2.1.10 Patched in 2.2.0
  61. 2023-05-24 CVE-2023-25799 Missing Authorization Affects <= 2.1.8 Patched in 2.1.9
  62. 2023-01-12 CVE-2023-0236 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.0.9 Patched in 2.0.10
  63. 2022-09-26 CVE-2022-2563 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.0.9 Patched in 2.0.10
  64. 2022-08-22 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects 2.0.0 - 2.0.8 Patched in 2.0.9
  65. 2021-12-27 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.9.11 Patched in 1.9.12
  66. 2021-12-27 CVE-2021-25017 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.9.11 Patched in 1.9.12
  67. 2021-10-19 CVE-2021-24873 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.9.10 Patched in 1.9.11
  68. 2021-09-20 CVE-2021-24740 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 1.9.9 Patched in 1.9.9
  69. 2021-08-09 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.9.5 Patched in 1.9.6
  70. 2021-06-28 CVE-2021-24455 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.9.1 Patched in 1.9.2
  71. 2021-04-05 CVE-2021-24242 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') Affects <= 1.8.7 Patched in 1.8.8
  72. 2021-03-15 CVE-2021-24184 Improper Privilege Management Affects < 1.7.7 Patched in 1.7.7
  73. 2021-03-15 CVE-2021-24183 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 1.8.2 Patched in 1.8.3
  74. 2021-03-15 CVE-2021-24185 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 1.7.7 Patched in 1.7.7
  75. 2021-03-15 CVE-2021-24181 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 1.7.7 Patched in 1.7.7
  76. 2021-03-15 CVE-2021-24182 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 1.8.2 Patched in 1.8.3
  77. 2021-03-15 CVE-2021-24186 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 1.8.3 Patched in 1.8.3
  78. 2021-01-10 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.9.12 Patched in 1.9.13
  79. 2020-02-04 CVE-2020-8615 Cross-Site Request Forgery (CSRF) Affects < 1.5.3 Patched in 1.5.3

Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.

CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.

Behavioral tests

via WP Hive

Automated install-time checks, tested on PHP 8.1.12 · WP 7.0.1

Low memory footprint
Low page-speed impact
Runs on latest PHP + WP
No PHP errors
No JS errors
Activates cleanly
No resource errors
No external HTTP errors
Optimized database use
Frequently updated

Languages

via translate.wordpress.org

Translated into 45 languages, 4 at 90% or more

Dutch 100%
Dutch (Formal) 100%
Finnish 99%
Spanish (Spain) 99%
Russian 81%
German 80%
German (Formal) 80%
Chinese (Taiwan) 76%
Persian 76%
Korean 75%
Lao 75%
Spanish (Chile) 74%
Arabic 66%
Bengali 64%
Romanian 56%
Swedish 54%
French (France) 45%
Vietnamese 45%
Czech 44%
Polish 43%
Ukrainian 38%
Norwegian (Bokmål) 37%
Italian 35%
Japanese 35%

Plus 21 more locales with partial translations.

Growth timeline

Install-tier crossings we have observed, and how long each tier took to outgrow

  1. 2025-02-08 90K+ → 100K+ up after 230 days in tier
  2. 2024-06-23 80K+ → 90K+ up after 1 days in tier
  3. 2024-06-22 90K+ → 80K+ down after 2 days in tier
  4. 2024-06-20 80K+ → 90K+ up after 197 days in tier
  5. 2023-12-06 70K+ → 80K+ up after 238 days in tier
  6. 2023-04-12 60K+ → 70K+ up after 176 days in tier
  7. 2022-10-18 50K+ → 60K+ up

Competes with

The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).

Compare head to head →

Embed this report card

Drop a live Pulse card for Tutor LMS – eLearning and online course solution into a readme, a review or a deck. It updates itself.

<iframe src="https://plugins.wpmayor.com/embed/tutor" width="480" height="300" style="border:0" loading="lazy" title="Tutor LMS – eLearning and online course solution — Plugin Pulse"></iframe>
Preview card ↗

Tutor LMS – eLearning and online course solution: 100K+ active installs, 4.4★ (587 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/tutor