
MembershipWorks Login Connector Security & Risk Analysis
wordpress.org/plugins/memberfindme-login-connectorAllows members to sign in to MembershipWorks and as a WordPress user on your site.
Is MembershipWorks Login Connector Safe to Use in 2026?
Generally Safe
Score 100/100MembershipWorks Login Connector has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The memberfindme-login-connector plugin version 6.4 exhibits a concerning security posture due to a significant number of unprotected entry points. All three identified AJAX handlers lack authentication checks, presenting a direct avenue for attackers to interact with potentially sensitive functionalities. While the plugin demonstrates good practices in its handling of SQL queries, ensuring they are prepared statements, and has no recorded vulnerability history, these strengths are overshadowed by the critical lack of authorization on its AJAX endpoints. The taint analysis also revealed flows with unsanitized paths, although these did not escalate to critical or high severity, they warrant attention as potential precursors to more severe issues if combined with exploitable entry points. The absence of nonce checks further exacerbates the risk associated with the unprotected AJAX handlers. Overall, while the plugin is free of known vulnerabilities and handles database interactions securely, its direct exposure of AJAX endpoints without proper authentication and authorization is a significant security weakness that requires immediate attention.
Key Concerns
- Unprotected AJAX handlers
- No nonce checks
- Unsanitized paths in taint flows
- Insufficient output escaping
MembershipWorks Login Connector Security Vulnerabilities
MembershipWorks Login Connector Code Analysis
Output Escaping
Data Flow Analysis
MembershipWorks Login Connector Attack Surface
AJAX Handlers 3
WordPress Hooks 13
Maintenance & Trust
MembershipWorks Login Connector Maintenance & Trust
Maintenance Signals
Community Trust
MembershipWorks Login Connector Alternatives
Wild Apricot Login
wild-apricot-login
Provides single sign-on service for Wild Apricot members to provide access to restricted Wild Apricot content.
Gym Studio Membership Management
gym-studio-membership-management
Gym Studio Membership Management adds class calendar, schedule of classes and membership checkout to your posts and pages.
Administrator Access to PMPro Protected Content
administrator-access-to-pmpro-protected-content
Overrides the PMPro "Require Membership" settings and grants view access to any user assigned to the WordPress "Administrator" rol …
MC Professional Authentication and User Sync
memberclicks-professional-authentication
Provides SSO (Single Sign-On) with MemberClicks Professional to restrict content based on member group. Sync user records for consistent access.
Membership Management
membership-management
Empower your organization with our Membership Management Plugin for WordPress. Effortlessly maintain and track membership status, contact details, and …
MembershipWorks Login Connector Developer Profile
4 plugins · 4K total installs
How We Detect MembershipWorks Login Connector
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/memberfindme-login-connector/style.css/wp-content/plugins/memberfindme-login-connector/scripts.js/wp-content/plugins/memberfindme-login-connector/scripts.jsmemberfindme-login-connector/style.css?ver=memberfindme-login-connector/scripts.js?ver=HTML / DOM Fingerprints
login-formlogin-usernamelogin-passwordlogin-submitlogin-requestlogin-messagelogin-ackwidget_sf_widget_login Copyright 2013-2023 SOURCEFOUND INC. (email : info@sourcefound.com) This program is free software; you can redistribute it and/or modify it under the terms of the GNU General Public License, version 2, as published by the Free Software Foundation.+7 moreonkeyuponclicksf_wpl/wp-json/sf_password/wp-json/sf_login/wp-json/sf_logout