Extended Shortcodes for Ultimate Membership Pro Security & Risk Analysis

wordpress.org/plugins/extended-shortcodes-for-ultimate-membership-pro

Extend Ultimate Membership Pro functionality with a list of shortcodes which can be used by admin in order to manage content restriction.

50 active installs v1.6 PHP 7.4+ WP 5.1.1+ Updated Apr 24, 2024
accessibilityextendfreeregistrationshortcode
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Extended Shortcodes for Ultimate Membership Pro Safe to Use in 2026?

Generally Safe

Score 92/100

Extended Shortcodes for Ultimate Membership Pro has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The plugin 'extended-shortcodes-for-ultimate-membership-pro' v1.6 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, the exclusive use of prepared statements for SQL queries, and complete output escaping for all identified outputs are significant strengths. Furthermore, the lack of file operations, external HTTP requests, and any recorded vulnerabilities in its history suggest diligent security practices by the developers.

However, a notable concern arises from the complete absence of nonce checks and capability checks across all its entry points, which include 7 shortcodes. While the static analysis reports no unprotected entry points, the lack of these fundamental security mechanisms creates potential vulnerabilities. If any of these shortcodes are to process user-supplied data in the future, especially in conjunction with AJAX or REST API calls (even if currently not implemented), they would be susceptible to Cross-Site Request Forgery (CSRF) attacks and privilege escalation if proper authorization checks are not added. The current lack of taint analysis results is also noted, though this may be due to the limited scope of the analysis or the absence of exploitable flows in the current version.

In conclusion, while the plugin demonstrates good practices in areas like SQL and output handling and has a clean vulnerability history, the absence of nonce and capability checks is a significant weakness. This oversight represents a potential risk, particularly as the plugin evolves or if future updates introduce new functionalities that handle user input. It is recommended that the developers address these missing checks to enhance the plugin's overall security.

Key Concerns

  • Missing nonce checks on all entry points
  • Missing capability checks on all entry points
Vulnerabilities
None known

Extended Shortcodes for Ultimate Membership Pro Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Extended Shortcodes for Ultimate Membership Pro Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
11 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped11 total outputs
Attack Surface

Extended Shortcodes for Ultimate Membership Pro Attack Surface

Entry Points7
Unprotected0

Shortcodes 7

[ump-logged-user] classes\Main.php:38
[ump-visitor] classes\Main.php:39
[ump-account-page-link] classes\Main.php:40
[ump-login-page-link] classes\Main.php:41
[ump-lost-password-page-link] classes\Main.php:42
[ump-register-page-link] classes\Main.php:43
[ump-subscription-page-link] classes\Main.php:44
WordPress Hooks 11
filterihc_magic_feature_listclasses\admin\Main.php:28
actionump_print_admin_pageclasses\admin\Main.php:30
actionadmin_enqueue_scriptsclasses\admin\Main.php:32
actionump_addon_action_before_print_admin_settingsclasses\admin\Main.php:35
filterihc_is_magic_feat_active_filterclasses\Main.php:29
actionwp_enqueue_scriptsclasses\Main.php:36
filterihc_default_options_group_filterclasses\Settings.php:35
actionplugins_loadedclasses\Utilities.php:50
actionadmin_noticesclasses\Utilities.php:64
actionadmin_noticesclasses\Utilities.php:71
actioninitextended-shortcodes-for-ultimate-membership-pro.php:16
Maintenance & Trust

Extended Shortcodes for Ultimate Membership Pro Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedApr 24, 2024
PHP min version7.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs50
Developer Profile

Extended Shortcodes for Ultimate Membership Pro Developer Profile

WPIndeed Development

5 plugins · 470 total installs

73
trust score
Avg Security Score
92/100
Avg Patch Time
329 days
View full developer profile
Detection Fingerprints

How We Detect Extended Shortcodes for Ultimate Membership Pro

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/extended-shortcodes-for-ultimate-membership-pro/assets/css/ump_es_admin_style.css/wp-content/plugins/extended-shortcodes-for-ultimate-membership-pro/assets/js/ump_es_admin_scripts.js
Script Paths
/wp-content/plugins/extended-shortcodes-for-ultimate-membership-pro/assets/js/ump_es_admin_scripts.js
Version Parameters
extended-shortcodes-for-ultimate-membership-pro/assets/css/ump_es_admin_style.css?ver=extended-shortcodes-for-ultimate-membership-pro/assets/js/ump_es_admin_scripts.js?ver=

HTML / DOM Fingerprints

CSS Classes
ump-es-admin-wrap
HTML Comments
<!-- EXTENDED SHORTCODES FOR ULTIMATE MEMBERSHIP PRO START --><!-- EXTENDED SHORTCODES FOR ULTIMATE MEMBERSHIP PRO END -->
Data Attributes
data-ump-es-what-it-does
Shortcode Output
[ump-logged-user][ump-visitor][ump-login-page-link][ump-account-page-link]
FAQ

Frequently Asked Questions about Extended Shortcodes for Ultimate Membership Pro