Admin Email for PMPro Membership Expiry Security & Risk Analysis

wordpress.org/plugins/admin-alert-email-for-pmpro-membership-expiry

Sends an email to the WordPress admin when a Paid Memberships Pro membership expires.

0 active installs v1.0.5 PHP 7.4+ WP 6.0+ Updated Jan 8, 2026
admin-notificationmembershipmembership-expirypaid-memberships-propmpro
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Admin Email for PMPro Membership Expiry Safe to Use in 2026?

Generally Safe

Score 100/100

Admin Email for PMPro Membership Expiry has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the 'admin-alert-email-for-pmpro-membership-expiry' plugin v1.0.5 appears to have a strong security posture. The static analysis shows no identified attack surface points such as AJAX handlers, REST API routes, or shortcodes. Furthermore, the code signals indicate no dangerous functions were used, all SQL queries are properly prepared, and output is consistently escaped. There are also no file operations or external HTTP requests, and importantly, no identified nonce checks or capability checks, which could be a concern if there were entry points. The taint analysis also reported no vulnerabilities.

The vulnerability history further reinforces this positive assessment, with no known CVEs, either historical or current. This absence of past vulnerabilities and the clean static analysis suggest that the developers are following good security practices. However, the complete lack of nonce checks and capability checks, while not posing an immediate risk given the zero identified entry points, represents a potential weakness. If new features were to be added that introduced any form of user interaction or data processing without proper authorization checks, it could become a significant security concern. The plugin's current strength lies in its limited attack surface and clean code, but future development should incorporate robust authentication and authorization mechanisms.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Admin Email for PMPro Membership Expiry Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Admin Email for PMPro Membership Expiry Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Admin Email for PMPro Membership Expiry Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionpmpro_membership_post_membership_expiryadmin-email-for-pmpro-membership-expiry.php:20
Maintenance & Trust

Admin Email for PMPro Membership Expiry Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 8, 2026
PHP min version7.4
Downloads164

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

Admin Email for PMPro Membership Expiry Developer Profile

Craze Collective

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Admin Email for PMPro Membership Expiry

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Admin Email for PMPro Membership Expiry