Membee Login Security & Risk Analysis

wordpress.org/plugins/membees-member-login-widget

Add member authentication and access role management to your WordPress site via Membee's powerful Member Single Sign-On web service.

200 active installs v2.3.7 PHP + WP 2.7.0+ Updated Feb 9, 2026
authenticationloginmembeemembersmembership
97
A · Safe
CVEs total1
Unpatched0
Last CVEJan 27, 2026
Download
Safety Verdict

Is Membee Login Safe to Use in 2026?

Generally Safe

Score 97/100

Membee Login has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jan 27, 2026Updated 1mo ago
Risk Assessment

The membees-member-login-widget v2.3.7 plugin presents a mixed security posture. On the positive side, the plugin demonstrates good practices by utilizing prepared statements for all SQL queries and appears to have no unpatched vulnerabilities in its history. The absence of dangerous functions, file operations, and external HTTP requests are also positive indicators. However, concerns arise from the significant percentage of improperly escaped output (66%). While the static analysis did not identify critical or high severity taint flows, the presence of 4 flows with unsanitized paths warrants attention, especially when combined with the output escaping issues. The vulnerability history, although showing no currently unpatched CVEs, does include a past high-severity vulnerability related to Cross-Site Scripting (XSS), indicating a historical weakness in input sanitization or output encoding. The large number of shortcodes (8) as entry points, while not explicitly stated as unprotected, could become a vector if not handled with robust sanitization and escaping, especially in light of the observed output escaping deficiency.

Key Concerns

  • Significant percentage of improperly escaped output
  • Flows with unsanitized paths found
  • Past high severity vulnerability (XSS)
Vulnerabilities
1

Membee Login Security Vulnerabilities

CVEs by Year

1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

High
1

1 total CVE

CVE-2025-68844high · 7.2Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Membee Login <= 2.3.6 - Unauthenticated Stored Cross-Site Scripting

Jan 27, 2026 Patched in 2.3.7 (15d)
Code Analysis
Analyzed Mar 16, 2026

Membee Login Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
48
25 escaped
Nonce Checks
2
Capability Checks
2
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

34% escaped73 total outputs
Data Flows
4 unsanitized

Data Flow Analysis

7 flows4 with unsanitized paths
membee_widget (mvc\v.php:107)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Membee Login Attack Surface

Entry Points8
Unprotected0

Shortcodes 8

[membee_login] membee-login.php:97
[membee_reset] membee-login.php:98
[member] wordpress-access-control.php:26
[members] wordpress-access-control.php:27
[non-members] wordpress-access-control.php:28
[nonmembers] wordpress-access-control.php:29
[non-member] wordpress-access-control.php:30
[nonmember] wordpress-access-control.php:31
WordPress Hooks 25
actionwidgets_initdefault-widgets.php:18
actionadmin_menumembee-login.php:32
actionadmin_print_stylesmembee-login.php:33
filterallowed_redirect_hostsmembee-login.php:34
actioninitmembee-login.php:106
filterlogout_urlmembee-login.php:108
actionafter_setup_themewordpress-access-control.php:5
actionwpwordpress-access-control.php:6
actionwpwordpress-access-control.php:7
actioninitwordpress-access-control.php:8
actionadmin_initwordpress-access-control.php:9
actionadmin_menuwordpress-access-control.php:10
actionadd_meta_boxeswordpress-access-control.php:11
actionsave_postwordpress-access-control.php:12
actionmanage_pages_custom_columnwordpress-access-control.php:13
filterget_pageswordpress-access-control.php:15
filtermanage_edit-page_columnswordpress-access-control.php:16
filterthe_excerptwordpress-access-control.php:17
filterthe_contentwordpress-access-control.php:18
filterplugin_row_metawordpress-access-control.php:19
filterposts_join_pagedwordpress-access-control.php:20
filterposts_where_pagedwordpress-access-control.php:21
filterwp_nav_menu_argswordpress-access-control.php:22
filterwp_nav_menu_argswordpress-access-control.php:23
filterwp_page_menu_argswordpress-access-control.php:24
Maintenance & Trust

Membee Login Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 9, 2026
PHP min version
Downloads22K

Community Trust

Rating68/100
Number of ratings5
Active installs200
Developer Profile

Membee Login Developer Profile

DaleAB

1 plugin · 200 total installs

92
trust score
Avg Security Score
97/100
Avg Patch Time
15 days
View full developer profile
Detection Fingerprints

How We Detect Membee Login

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/membees-member-login-widget/css/membee-login-widget.css/wp-content/plugins/membees-member-login-widget/js/membee-login-widget.js
Script Paths
/wp-content/plugins/membees-member-login-widget/js/membee-login-widget.js
Version Parameters
membees-member-login-widget/css/membee-login-widget.css?ver=membees-member-login-widget/js/membee-login-widget.js?ver=

HTML / DOM Fingerprints

CSS Classes
membee-login-widget-containermembee-login-widget-titlemembee-login-widget-subtitle
Data Attributes
data-membee-widget-id
JS Globals
membee_login_widget_settings
Shortcode Output
[membee_login][membee_reset]
FAQ

Frequently Asked Questions about Membee Login