
Login with YourMembership – YM SSO Login Security & Risk Analysis
wordpress.org/plugins/login-with-yourmembershipSingle Sign On (SSO) into WordPress (WP) using YourMembership credentials - Login with YourMembership [24/7 SUPPORT]
Is Login with YourMembership – YM SSO Login Safe to Use in 2026?
Generally Safe
Score 97/100Login with YourMembership – YM SSO Login has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The plugin exhibits a mixed security posture. On the positive side, the static analysis reveals no immediately obvious vulnerabilities in terms of attack surface (no unprotected AJAX, REST API, shortcodes, or cron events) and a strong adherence to secure coding practices with 100% of SQL queries using prepared statements and a high percentage of output properly escaped. Furthermore, there are a reasonable number of nonce and capability checks. However, the presence of 4 external HTTP requests and 6 taint flows with unsanitized paths, even if not rated as critical or high severity, warrants attention as potential vectors for unexpected behavior or vulnerabilities if exploited by malicious input. The vulnerability history is a significant concern, with 3 known medium-severity CVEs, all of which are listed as currently unpatched. The common vulnerability types of Missing Authorization and Cross-site Scripting are particularly worrying, suggesting a pattern of insecure handling of user input and access control in past versions. While the current version appears to have addressed these specific CVEs, the historical pattern indicates a potential for similar issues to re-emerge if not rigorously tested and audited. Overall, while the current code has some strengths, the historical vulnerability data and the presence of unsanitized taint flows suggest a moderate level of risk.
Key Concerns
- Unpatched CVEs (3 medium)
- Flows with unsanitized paths
- External HTTP requests
Login with YourMembership – YM SSO Login Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Login with YourMembership - YM SSO Login <= 1.1.7 - Missing Authorization to Unauthenticated Sensitive Information Exposure via 'moym_display_test_attributes'
YourMembership Single Sign On <= 1.1.3 - Authenticated (Administrator+) Stored Cross-Site Scripting via plugin settings
YourMembership Single Sign On <= 1.1.3 - Missing Authorization
Login with YourMembership – YM SSO Login Release Timeline
Login with YourMembership – YM SSO Login Code Analysis
Output Escaping
Data Flow Analysis
Login with YourMembership – YM SSO Login Attack Surface
WordPress Hooks 12
Maintenance & Trust
Login with YourMembership – YM SSO Login Maintenance & Trust
Maintenance Signals
Community Trust
Login with YourMembership – YM SSO Login Alternatives
WP-Members Membership Plugin
wp-members
The original WordPress membership plugin with content restriction, user login, custom registration fields, user profiles, and more.
Simple Membership After Login Redirection
simple-membership-after-login-redirection
An addon for the simple membership plugin to configure after login redirection to a specific page based on the member's level.
WP Login Form
wp-login-form
Create a WordPress login form and add it to your post, page or sidebar
Expire User Passwords
expire-user-passwords
Require certain users to change their passwords on a regular basis.
Pie Register – User Registration, Profiles & Content Restriction
pie-register
Create customized registration forms, Invite through email, Email Notification, User Roles assignment, and more. Pie Register is a User Registration p …
Login with YourMembership – YM SSO Login Developer Profile
41 plugins · 83K total installs
How We Detect Login with YourMembership – YM SSO Login
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/login-with-yourmembership/includes/css/moym_style.min.css/wp-content/plugins/login-with-yourmembership/includes/css/phone.css/wp-content/plugins/login-with-yourmembership/includes/js/phone.js/wp-content/plugins/login-with-yourmembership/includes/js/settings.js/wp-content/plugins/login-with-yourmembership/includes/js/phone.js/wp-content/plugins/login-with-yourmembership/includes/js/settings.jslogin-with-yourmembership/includes/css/moym_style.min.css?ver=login-with-yourmembership/includes/css/phone.css?ver=login-with-yourmembership/includes/js/phone.js?ver=login-with-yourmembership/includes/js/settings.js?ver=HTML / DOM Fingerprints
moym_table_layoutmoym_plugin_dirmoym_plugin_path