Login with YourMembership – YM SSO Login Security & Risk Analysis

wordpress.org/plugins/login-with-yourmembership

Single Sign On (SSO) into WordPress (WP) using YourMembership credentials - Login with YourMembership [24/7 SUPPORT]

10 active installs v1.1.8 PHP 5.4+ WP 3.7+ Updated Nov 4, 2025
loginmembershipmembership-loginym-loginyourmembership
97
A · Safe
CVEs total3
Unpatched0
Last CVEOct 14, 2025
Safety Verdict

Is Login with YourMembership – YM SSO Login Safe to Use in 2026?

Generally Safe

Score 97/100

Login with YourMembership – YM SSO Login has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

3 known CVEsLast CVE: Oct 14, 2025Updated 6mo ago
Risk Assessment

The plugin exhibits a mixed security posture. On the positive side, the static analysis reveals no immediately obvious vulnerabilities in terms of attack surface (no unprotected AJAX, REST API, shortcodes, or cron events) and a strong adherence to secure coding practices with 100% of SQL queries using prepared statements and a high percentage of output properly escaped. Furthermore, there are a reasonable number of nonce and capability checks. However, the presence of 4 external HTTP requests and 6 taint flows with unsanitized paths, even if not rated as critical or high severity, warrants attention as potential vectors for unexpected behavior or vulnerabilities if exploited by malicious input. The vulnerability history is a significant concern, with 3 known medium-severity CVEs, all of which are listed as currently unpatched. The common vulnerability types of Missing Authorization and Cross-site Scripting are particularly worrying, suggesting a pattern of insecure handling of user input and access control in past versions. While the current version appears to have addressed these specific CVEs, the historical pattern indicates a potential for similar issues to re-emerge if not rigorously tested and audited. Overall, while the current code has some strengths, the historical vulnerability data and the presence of unsanitized taint flows suggest a moderate level of risk.

Key Concerns

  • Unpatched CVEs (3 medium)
  • Flows with unsanitized paths
  • External HTTP requests
Vulnerabilities
3 published

Login with YourMembership – YM SSO Login Security Vulnerabilities

CVEs by Year

2 CVEs in 2023
2023
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
3

3 total CVEs

CVE-2025-10648medium · 5.3Missing Authorization

Login with YourMembership - YM SSO Login <= 1.1.7 - Missing Authorization to Unauthenticated Sensitive Information Exposure via 'moym_display_test_attributes'

Oct 14, 2025 Patched in 1.1.8 (24d)
CVE-2023-37986medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

YourMembership Single Sign On <= 1.1.3 - Authenticated (Administrator+) Stored Cross-Site Scripting via plugin settings

Jul 17, 2023 Patched in 1.1.4 (190d)
CVE-2023-37987medium · 6.5Missing Authorization

YourMembership Single Sign On <= 1.1.3 - Missing Authorization

Jul 17, 2023 Patched in 1.1.4 (190d)
Code Analysis
Analyzed Mar 17, 2026

Login with YourMembership – YM SSO Login Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
111 escaped
Nonce Checks
4
Capability Checks
9
File Operations
0
External Requests
4
Bundled Libraries
0

Output Escaping

97% escaped114 total outputs
Data Flows · Security
6 unsanitized

Data Flow Analysis

6 flows6 with unsanitized paths
<class-moym-sso> (class-moym-sso.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Login with YourMembership – YM SSO Login Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actioninitclass-moym-sso.php:44
actionadmin_footerclass-moym-sso.php:45
actionwidgets_initclass-moym-sso.php:46
actionlogin_formclass-moym-sso.php:52
actionadmin_noticesincludes\utils\class-moym-utility.php:59
actionadmin_noticesincludes\utils\class-moym-utility.php:67
actionadmin_menumoym-settings.php:51
actionadmin_initmoym-settings.php:52
actionadmin_enqueue_scriptsmoym-settings.php:54
actionlogin_enqueue_scriptsmoym-settings.php:55
actionlogin_enqueue_scriptsmoym-settings.php:56
actionadmin_enqueue_scriptsmoym-settings.php:57
Maintenance & Trust

Login with YourMembership – YM SSO Login Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 4, 2025
PHP min version5.4
Downloads3K

Community Trust

Rating100/100
Number of ratings3
Active installs10
Developer Profile

Login with YourMembership – YM SSO Login Developer Profile

miniOrange

41 plugins · 83K total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
324 days
View full developer profile
Detection Fingerprints

How We Detect Login with YourMembership – YM SSO Login

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/login-with-yourmembership/includes/css/moym_style.min.css/wp-content/plugins/login-with-yourmembership/includes/css/phone.css/wp-content/plugins/login-with-yourmembership/includes/js/phone.js/wp-content/plugins/login-with-yourmembership/includes/js/settings.js
Script Paths
/wp-content/plugins/login-with-yourmembership/includes/js/phone.js/wp-content/plugins/login-with-yourmembership/includes/js/settings.js
Version Parameters
login-with-yourmembership/includes/css/moym_style.min.css?ver=login-with-yourmembership/includes/css/phone.css?ver=login-with-yourmembership/includes/js/phone.js?ver=login-with-yourmembership/includes/js/settings.js?ver=

HTML / DOM Fingerprints

CSS Classes
moym_table_layout
JS Globals
moym_plugin_dirmoym_plugin_path
FAQ

Frequently Asked Questions about Login with YourMembership – YM SSO Login