
E20R Better Members List for Paid Memberships Pro Security & Risk Analysis
wordpress.org/plugins/e20r-members-listExtensible, sortable & bulk action capable members listing + export to CSV tool for Paid Memberships Pro.
Is E20R Better Members List for Paid Memberships Pro Safe to Use in 2026?
Generally Safe
Score 85/100E20R Better Members List for Paid Memberships Pro has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The e20r-members-list plugin v8.6 exhibits a generally good security posture with several strengths. The absence of known CVEs and recorded vulnerabilities, combined with a relatively low number of SQL queries and a high percentage of prepared statements, indicates a careful approach to data handling. The presence of nonce and capability checks, along with a decent rate of output escaping, further reinforces this. However, a significant concern arises from the attack surface analysis, specifically the presence of AJAX handlers without authentication checks. This creates a direct entry point for potential malicious actors to interact with the plugin without proper authorization, posing a tangible risk.
The taint analysis showing zero flows with unsanitized paths is a positive sign, suggesting that direct code injection vulnerabilities are not immediately apparent. Nonetheless, the single unprotected AJAX handler remains a critical point of attention. The plugin's history of no vulnerabilities is encouraging, but it does not negate the risks identified in the static analysis, especially concerning the unprotected entry point. The bundled outdated jQuery library, while not a critical flaw on its own, is a minor weakness that could be exploited in conjunction with other issues.
In conclusion, while the plugin demonstrates good practices in many areas, the unprotected AJAX handler is a notable weakness that warrants immediate attention. The lack of past vulnerabilities is a strength, but the identified static analysis findings must be addressed to maintain a robust security profile. Focusing on securing all entry points and updating bundled libraries will be crucial for fortifying the plugin.
Key Concerns
- Unprotected AJAX handler
- Bundled outdated jQuery library
E20R Better Members List for Paid Memberships Pro Security Vulnerabilities
E20R Better Members List for Paid Memberships Pro Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
E20R Better Members List for Paid Memberships Pro Attack Surface
AJAX Handlers 2
WordPress Hooks 26
Maintenance & Trust
E20R Better Members List for Paid Memberships Pro Maintenance & Trust
Maintenance Signals
Community Trust
E20R Better Members List for Paid Memberships Pro Alternatives
myCred Paid Memberships Pro
mycred-paid-memberships-pro
📢🚨Important Notice: myCred Paid Memberships Pro is now part of the myCred Toolkit and will no longer receive updates here.
Administrator Access to PMPro Protected Content
administrator-access-to-pmpro-protected-content
Overrides the PMPro "Require Membership" settings and grants view access to any user assigned to the WordPress "Administrator" rol …
IDPay For Paid Memberships Pro
idpay-paid-memberships-pro
After installing and enabling this plugin, your customers can pay through IDPay gateway.
AURPAY Paid Memberships Pro (PMP) – Bitcoin Crypto Payment Gateway
aurpay-crypto-payment-for-paid-memberships-pro
Accept ETH, USDC, USDT, DAI, BTC & Lightning in PMP. Non-custodial, low fees, no card chargebacks.
Click & Pledge – Paid Memberships Pro
click-pledge-paid-memberships-pro
Click & Pledge payment gateway integration for Paid Memberships Pro with Salesforce support.
E20R Better Members List for Paid Memberships Pro Developer Profile
3 plugins · 170 total installs
How We Detect E20R Better Members List for Paid Memberships Pro
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/e20r-members-list/assets/css/e20r-members-list.css/wp-content/plugins/e20r-members-list/assets/js/e20r-members-list.js/wp-content/plugins/e20r-members-list/assets/js/e20r-members-list.jse20r-members-list/assets/css/e20r-members-list.css?ver=e20r-members-list/assets/js/e20r-members-list.js?ver=HTML / DOM Fingerprints
e20r-members-list-wrapper<!-- Members List generated by E20R Members List plugin --><!-- E20R Members List plugin - Footer JS -->data-e20r-ml-optionse20r_members_list_params[e20r_members_list]