MembershipWorks Login Connector Security & Risk Analysis

wordpress.org/plugins/memberfindme-login-connector

Allows members to sign in to MembershipWorks and as a WordPress user on your site.

800 active installs v6.4 PHP + WP 4.0+ Updated Feb 22, 2026
member-loginmemberfindmemembershipmembership-managementmembershipworks
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is MembershipWorks Login Connector Safe to Use in 2026?

Generally Safe

Score 100/100

MembershipWorks Login Connector has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The memberfindme-login-connector plugin version 6.4 exhibits a concerning security posture due to a significant number of unprotected entry points. All three identified AJAX handlers lack authentication checks, presenting a direct avenue for attackers to interact with potentially sensitive functionalities. While the plugin demonstrates good practices in its handling of SQL queries, ensuring they are prepared statements, and has no recorded vulnerability history, these strengths are overshadowed by the critical lack of authorization on its AJAX endpoints. The taint analysis also revealed flows with unsanitized paths, although these did not escalate to critical or high severity, they warrant attention as potential precursors to more severe issues if combined with exploitable entry points. The absence of nonce checks further exacerbates the risk associated with the unprotected AJAX handlers. Overall, while the plugin is free of known vulnerabilities and handles database interactions securely, its direct exposure of AJAX endpoints without proper authentication and authorization is a significant security weakness that requires immediate attention.

Key Concerns

  • Unprotected AJAX handlers
  • No nonce checks
  • Unsanitized paths in taint flows
  • Insufficient output escaping
Vulnerabilities
None known

MembershipWorks Login Connector Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

MembershipWorks Login Connector Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
15 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
3
Bundled Libraries
0

Output Escaping

63% escaped24 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
sf_password (memberfindmelogin.php:298)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
3 unprotected

MembershipWorks Login Connector Attack Surface

Entry Points3
Unprotected3

AJAX Handlers 3

noprivwp_ajax_sf_passwordmemberfindmelogin.php:78
noprivwp_ajax_sf_loginmemberfindmelogin.php:80
authwp_ajax_sf_logoutmemberfindmelogin.php:82
WordPress Hooks 13
actioninitmemberfindmelogin.php:102
actionclear_auth_cookiememberfindmelogin.php:112
filternocache_headersmemberfindmelogin.php:118
actionwidgets_initmemberfindmelogin.php:176
filtersend_email_change_emailmemberfindmelogin.php:204
filtersend_password_change_emailmemberfindmelogin.php:205
actionlogin_form_loginmemberfindmelogin.php:242
actionwp_authenticatememberfindmelogin.php:279
actionlogin_form_logoutmemberfindmelogin.php:295
actionwp_logoutmemberfindmelogin.php:296
actionlogin_form_lostpasswordmemberfindmelogin.php:357
actionlogin_form_retrievepasswordmemberfindmelogin.php:358
filterget_avatarmemberfindmelogin.php:371
Maintenance & Trust

MembershipWorks Login Connector Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 22, 2026
PHP min version
Downloads31K

Community Trust

Rating100/100
Number of ratings2
Active installs800
Developer Profile

MembershipWorks Login Connector Developer Profile

MembershipWorks

4 plugins · 4K total installs

94
trust score
Avg Security Score
92/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect MembershipWorks Login Connector

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/memberfindme-login-connector/style.css/wp-content/plugins/memberfindme-login-connector/scripts.js
Script Paths
/wp-content/plugins/memberfindme-login-connector/scripts.js
Version Parameters
memberfindme-login-connector/style.css?ver=memberfindme-login-connector/scripts.js?ver=

HTML / DOM Fingerprints

CSS Classes
login-formlogin-usernamelogin-passwordlogin-submitlogin-requestlogin-messagelogin-ackwidget_sf_widget_login
HTML Comments
Copyright 2013-2023 SOURCEFOUND INC. (email : info@sourcefound.com) This program is free software; you can redistribute it and/or modify it under the terms of the GNU General Public License, version 2, as published by the Free Software Foundation.+7 more
Data Attributes
onkeyuponclick
JS Globals
sf_wpl
REST Endpoints
/wp-json/sf_password/wp-json/sf_login/wp-json/sf_logout
FAQ

Frequently Asked Questions about MembershipWorks Login Connector