Membrio – Member Directory Security & Risk Analysis

wordpress.org/plugins/membrio-member-directory

A simple and flexible WordPress plugin to manage members and associate them with multiple teams.

0 active installs v1.0.0 PHP 7.4+ WP 5.5+ Updated Nov 2, 2025
contact-formcustom-post-typedirectorymembersteams
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Membrio – Member Directory Safe to Use in 2026?

Generally Safe

Score 100/100

Membrio – Member Directory has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The membrio-member-directory plugin v1.0.0 demonstrates an exceptionally strong security posture based on the provided static analysis and vulnerability history. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points is a significant strength, minimizing the potential attack surface. Code analysis reveals excellent practices such as 100% prepared SQL statements, nearly perfect output escaping (99%), and the presence of nonce and capability checks. The plugin also avoids dangerous functions, file operations, and external HTTP requests, further reducing risk.

The lack of any recorded vulnerabilities, including critical or high severity CVEs, and the absence of any taint analysis findings, reinforces the impression of a well-secured plugin. This indicates diligent development and a proactive approach to security. However, the analysis of only 0 taint flows is notable; while ideal, it might also mean the analysis itself was limited in scope for this plugin, or the plugin's functionality is extremely basic, thus not generating complex data flows that would require taint analysis. The plugin's limited functionality, suggested by the lack of entry points, contributes to its strong security profile.

In conclusion, membrio-member-directory v1.0.0 appears to be a highly secure plugin, exhibiting best practices in code security and benefiting from a clean vulnerability history. The primary strength lies in its minimal and well-protected attack surface. The lack of any identified issues is a strong positive indicator. The only potential point of consideration is the limited scope indicated by the 0 taint flows, which, if due to very basic functionality, is not a concern, but if it implies an incomplete analysis, could be a minor caveat to the otherwise glowing assessment.

Vulnerabilities
None known

Membrio – Member Directory Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Membrio – Member Directory Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
1
94 escaped
Nonce Checks
5
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

99% escaped95 total outputs
Attack Surface

Membrio – Member Directory Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 16
filtermanage_medir_member_posts_columnsincludes\Admin\class-custom-user-column.php:5
actioninitincludes\Admin\class-email-submission-handler.php:5
actionmanage_medir_member_posts_custom_columnincludes\Admin\class-fill-custom-column-value.php:5
actionadmin_enqueue_scriptsincludes\Assets\class-include-assets.php:9
actionwp_enqueue_scriptsincludes\Assets\class-include-assets.php:10
filtersingle_templateincludes\class-load-template.php:11
filtersingle_templateincludes\class-load-template.php:12
filterarchive_templateincludes\class-load-template.php:13
filterarchive_templateincludes\class-load-template.php:14
actionadd_meta_boxesincludes\post-type\class-add-meta-box.php:8
actionsave_post_medir_memberincludes\post-type\class-member-hendler.php:6
actionsave_post_medir_memberincludes\post-type\class-member-hendler.php:44
actioninitincludes\post-type\class-register-post-type.php:5
actionsave_post_medir_memberincludes\post-type\class-save-post-handler.php:9
actionsave_post_medir_memberincludes\post-type\class-save-post-handler.php:10
filterwp_insert_post_dataincludes\post-type\class-save-post-handler.php:11
Maintenance & Trust

Membrio – Member Directory Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 2, 2025
PHP min version7.4
Downloads137

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Membrio – Member Directory Developer Profile

Md Hazrath Ali

4 plugins · 100 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Membrio – Member Directory

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/membrio-member-directory/includes/Assets/assets-loader/trait-admin-assets-helper.php/wp-content/plugins/membrio-member-directory/includes/Assets/assets-loader/trait-fontend-assets-helper.php/wp-content/plugins/membrio-member-directory/includes/Assets/class-include-assets.php/wp-content/plugins/membrio-member-directory/includes/Admin/class-email-submission-handler.php/wp-content/plugins/membrio-member-directory/includes/Admin/class-fill-custom-column-value.php/wp-content/plugins/membrio-member-directory/includes/class-loader.php
Script Paths
../assets/css/admin-style.css../assets/js/admin-main.js../assets/css/bootstrap.min.css../assets/css/frontend-style.css
Version Parameters
membrio-member-directory/style.css?ver=1.0.0membrio-member-directory/script.js?ver=1.0.0

HTML / DOM Fingerprints

CSS Classes
medir-main-cssmedir-admin-jsmedir-bootstrap-cssmedir-main-css
Data Attributes
medir_form_nonce_medir_member_email_medir_message_medir_sender_email_medir_sender_name_medir_first_name+4 more
JS Globals
medir_admin_enqueue_scriptsmedir_frontend_enqueue_scriptsMEDIR_Email_Submission_HandlerMEDIR_Fill_Custom_Column_ValueMEDIR_Autoloader
FAQ

Frequently Asked Questions about Membrio – Member Directory