Gym Studio Membership Management Security & Risk Analysis

wordpress.org/plugins/gym-studio-membership-management

Gym Studio Membership Management adds class calendar, schedule of classes and membership checkout to your posts and pages.

90 active installs v1.2.0 PHP + WP 4.2.4+ Updated Jul 2, 2025
class-calendarclass-schedulemembermembership-managementschedule-of-classes
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Gym Studio Membership Management Safe to Use in 2026?

Generally Safe

Score 100/100

Gym Studio Membership Management has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9mo ago
Risk Assessment

The gym-studio-membership-management plugin v1.2.0 exhibits a generally strong security posture, with several positive indicators. The absence of known CVEs and a clean vulnerability history are significant strengths, suggesting a history of good security practices by the developers. The static analysis also reveals a low attack surface with no unprotected entry points, minimal SQL queries, and a high percentage of properly escaped output. External HTTP requests are present but do not pose an immediate concern without further context.

However, there are notable areas for improvement and potential underlying risks. The complete lack of nonce checks and capability checks across all analyzed entry points is a critical oversight. This means that any user, regardless of their role or permissions, could potentially trigger the plugin's functionalities, leading to unauthorized actions. While taint analysis shows no critical or high severity flows currently, the absence of checks means that if a vulnerability were introduced in the future, it could be easily exploited. The static analysis does not indicate any direct vulnerabilities, but the identified missing security controls are significant concerns that warrant immediate attention.

Key Concerns

  • Missing Nonce Checks
  • Missing Capability Checks
  • External HTTP Requests Present
Vulnerabilities
None known

Gym Studio Membership Management Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Gym Studio Membership Management Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
3 prepared
Unescaped Output
4
27 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
3
Bundled Libraries
0

SQL Query Safety

75% prepared4 total queries

Output Escaping

87% escaped31 total outputs
Attack Surface

Gym Studio Membership Management Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[fitsoft-code] membership-management.php:154
WordPress Hooks 18
filterblock_categoriesblock\index.php:25
actioninitblock\index.php:76
actioninitmembership-management-buttons.php:2
filtermce_external_pluginsmembership-management-buttons.php:8
filtermce_buttonsmembership-management-buttons.php:9
actionadmin_menumembership-management-common.php:2
actionadmin_menumembership-management-options.php:18
actionadmin_initmembership-management-options.php:19
actionadmin_menumembership-management-options.php:51
actionadmin_initmembership-management-options.php:52
actioninitmembership-management.php:130
actionwp_headmembership-management.php:140
actionadmin_enqueue_scriptsmembership-management.php:242
actionwp_enqueue_scriptsmembership-management.php:265
actionwp_enqueue_scriptsmembership-management.php:266
actionwp_footermembership-management.php:371
actionadmin_footermembership-management.php:373
actionadmin_enqueue_scriptsmembership-management.php:375
Maintenance & Trust

Gym Studio Membership Management Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJul 2, 2025
PHP min version
Downloads22K

Community Trust

Rating78/100
Number of ratings15
Active installs90
Developer Profile

Gym Studio Membership Management Developer Profile

Fitsoft

1 plugin · 90 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Gym Studio Membership Management

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gym-studio-membership-management/js/fitsoftsettingopt-plugin.js/wp-content/plugins/gym-studio-membership-management/css/fitsoft-dnsprefetch.css
Script Paths
https://admin.fitsoft.com/js/lib/app.all.ahttps://admin.fitsoft.com/js/lib/app.all.b
Version Parameters
gym-studio-membership-management/js/fitsoftsettingopt-plugin.js?ver=1.2.0

HTML / DOM Fingerprints

CSS Classes
fsframeinfo
Data Attributes
data-page-namedata-page-guiddata-page-default-heightdata-isloader-on
Shortcode Output
<div id='fsframeinfo
FAQ

Frequently Asked Questions about Gym Studio Membership Management