
MembershipWorks – Membership, Events & Directory Security & Risk Analysis
wordpress.org/plugins/memberfindmeAll-in-one membership, directory, events and donations for organizations. Secure member profiles, renewals, upgrades and limit member only access to c …
Is MembershipWorks – Membership, Events & Directory Safe to Use in 2026?
Generally Safe
Score 99/100MembershipWorks – Membership, Events & Directory has a strong security track record. Known vulnerabilities have been patched promptly.
The 'memberfindme' v6.15 plugin demonstrates a generally good security posture with several positive indicators. The absence of identified AJAX handlers, REST API routes, shortcodes, and cron events with unprotected entry points is a significant strength, indicating a limited attack surface that is well-secured. The code also shows strong adherence to secure coding practices with 100% of SQL queries using prepared statements and a high percentage (92%) of outputs being properly escaped, mitigating common vulnerabilities like SQL injection and Cross-Site Scripting. The presence of capability checks also suggests an effort to enforce WordPress's permission system.
However, there are areas for concern. The static analysis revealed one flow with an unsanitized path, which, while not classified as critical or high severity in the taint analysis, still represents a potential avenue for exploitation. The single external HTTP request, while not inherently a vulnerability, warrants careful review to ensure it doesn't expose the site to risks from compromised external resources. The complete lack of nonce checks, especially if there are any hidden or undocumented entry points, is a significant weakness that could allow for Cross-Site Request Forgery (CSRF) attacks. Furthermore, the plugin's vulnerability history shows one past medium-severity Cross-Site Scripting vulnerability, indicating that while the current version may be patched, the plugin has a history of such issues, suggesting a need for continued vigilance.
In conclusion, 'memberfindme' v6.15 is in a reasonably secure state due to its limited attack surface and good use of prepared statements and output escaping. Nevertheless, the presence of an unsanitized path, the lack of nonce checks, and the past XSS vulnerability are important considerations. The plugin's strengths lie in its foundational secure coding practices, but its weaknesses lie in potential unaddressed entry points and a historical pattern of XSS issues, suggesting that while risk is currently low, it's not entirely absent.
Key Concerns
- Flow with unsanitized path
- Missing nonce checks
- External HTTP request
- Past medium severity CVE
MembershipWorks – Membership, Events & Directory Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
MembershipWorks <= 6.14 - Authenticated (Admin+) Stored Cross-Site Scripting
MembershipWorks – Membership, Events & Directory Code Analysis
Output Escaping
Data Flow Analysis
MembershipWorks – Membership, Events & Directory Attack Surface
WordPress Hooks 21
Maintenance & Trust
MembershipWorks – Membership, Events & Directory Maintenance & Trust
Maintenance Signals
Community Trust
MembershipWorks – Membership, Events & Directory Alternatives
Events Manager – Calendar, Bookings, Tickets, and more!
events-manager
Events calendar with bookings, scheduling, appointments, event registration, tickets, recurring events, and venue management.
WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce
wp-event-manager
Lightweight, scalable and full-featured event listings & management plugin for managing events & tickets from the Frontend and Backend.
User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration
wp-user-frontend
Create forms, guest posts, subscriptions, user directory, user registration, membership, frontend posts, profile builder, content restriction rules.
Sugar Calendar – Events Calendar, Event Tickets, and Events Management Platform
sugar-calendar-lite
Easily manage events and sell tickets on your WordPress site. Sugar Calendar is easy-to-use, reliable, and exceptionally powerful. See for yourself.
Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered)
wp-event-solution
Create and manage events with a flexible WordPress events calendar plugin. Add recurring events, RSVP, ticket booking, and WooCommerce ticket selling …
MembershipWorks – Membership, Events & Directory Developer Profile
4 plugins · 4K total installs
How We Detect MembershipWorks – Membership, Events & Directory
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/memberfindme/sf-style.css/wp-content/plugins/memberfindme/sf-maps.js/wp-content/plugins/memberfindme/sf-members.js/wp-content/plugins/memberfindme/sf-events.js/wp-content/plugins/memberfindme/sf-forms.js/wp-content/plugins/memberfindme/sf-widgets.js/wp-content/plugins/memberfindme/sf-style.css/wp-content/plugins/memberfindme/sf-maps.js/wp-content/plugins/memberfindme/sf-members.js/wp-content/plugins/memberfindme/sf-events.js/wp-content/plugins/memberfindme/sf-forms.js/wp-content/plugins/memberfindme/sf-widgets.jsmemberfindme/sf-style.css?ver=memberfindme/sf-maps.js?ver=memberfindme/sf-members.js?ver=memberfindme/sf-events.js?ver=memberfindme/sf-forms.js?ver=memberfindme/sf-widgets.js?ver=HTML / DOM Fingerprints
sf_widgetsf_membersf_eventsf_formsf_member_profilesf_event_detailssf_donation_formdata-sf-orgiddata-sf-memberiddata-sf-eventiddata-sf-formidsf_api_settings[membershipworks_directory][membershipworks_members][membershipworks_events][membershipworks_forms]