LifterLMS
WordPress LMS plugin for creating and selling online courses with memberships, quizzes, and certificates.
A WordPress LMS that just made its whole REST surface discoverable to AI clients.
◆Recent moves
- 20h ago
10.1.1: order key entropy plus Course Builder and block editor fixes
A cleanup release a week after 10.1.0: more entropy in order keys, and fixes for access plans not saving from the block editor, duplicate engagement emails when multiple emails share a trigger, and lesson completion rejected at the exact moment the minimum time requirement was met. The mix of a hardening item with editor bugs matches the pattern of the last several months.
View source ↗ - 7d ago
10.1.0: REST endpoints registered as WordPress Abilities for AI clients
⚡ SPARKThe release that turns LifterLMS into something an agent can operate: every major REST endpoint registered as a discoverable ability under WordPress 6.9's Abilities API, plus wp llms commands that return course structure and enrollments in one call and a written guide for Claude Code, Cursor and Codex. It reframes the plugin from a site feature into a data surface other software drives.
View source ↗ - 1mo ago
10.0.10: pricing markup sanitization and post-search AJAX checks
Two externally reported security fixes covering pricing display markup and post search AJAX requests. Part of the June hardening run that precedes opening the REST surface to agents.
View source ↗ - 1mo ago
10.0.9: tighter checks on quiz start and REST authentication
Additional checks when starting a quiz, on the add-ons screen, and when authenticating REST API requests. The REST authentication item is directly relevant to what 10.1.0 would later expose.
View source ↗ - 1mo ago
10.0.8: checkout, import and registration form validation
Three security fixes from a single outside reporter covering checkout order creation, user creation during imports, and account and registration form submissions. All on paths that create records rather than read them.
View source ↗ - 1mo ago
10.0.7: anonymous visitors no longer break full-page caching
Session cookies are withheld from anonymous visitors until session data is actually written, so ordinary page views stay eligible for full-page caching instead of bypassing it. A real throughput change for content-heavy course sites, bundled with more input validation fixes.
View source ↗