MyASP MemberShip Security & Risk Analysis

wordpress.org/plugins/myasp-membership

Membership plugin for MyASP Users.

100 active installs v1.0.6 PHP 7.3.33+ WP 5.9.4+ Updated Jun 11, 2025
access-controlloginmembermembershipuser-registration
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is MyASP MemberShip Safe to Use in 2026?

Generally Safe

Score 100/100

MyASP MemberShip has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9mo ago
Risk Assessment

The "myasp-membership" plugin v1.0.6 exhibits a generally good security posture based on the provided static analysis. The absence of unprotected AJAX handlers and REST API routes, coupled with the fact that all identified SQL queries utilize prepared statements and the vast majority of output is properly escaped, are strong indicators of secure coding practices. The plugin also demonstrates a commitment to security by implementing nonce checks in several areas. However, there are a few areas that warrant attention. The presence of 4 flows with unsanitized paths in the taint analysis, although not flagged as critical or high severity, suggests a potential for input validation issues that could be exploited if they interact with sensitive operations. Additionally, the plugin makes an external HTTP request, which could be a vector for certain types of attacks if not handled with extreme care and proper validation of the response. The plugin's vulnerability history is completely clean, with no recorded CVEs, which is a significant strength. This, combined with the generally strong static analysis results, suggests a well-maintained and relatively secure plugin. In conclusion, while "myasp-membership" v1.0.6 has notable strengths in its security implementation, the taint analysis highlighting unsanitized paths and the external HTTP request introduce minor but present risks that should be addressed.

Key Concerns

  • Flows with unsanitized paths
  • External HTTP request detected
Vulnerabilities
None known

MyASP MemberShip Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

MyASP MemberShip Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
133 escaped
Nonce Checks
7
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

99% escaped134 total outputs
Data Flows
4 unsanitized

Data Flow Analysis

5 flows4 with unsanitized paths
myasp_access_controller (myasp-membership.php:560)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

MyASP MemberShip Attack Surface

Entry Points33
Unprotected0

REST API Routes 1

GET/wp-json/myasp/v1/tagsmyasp-membership.php:3165

Shortcodes 32

[myasp_login_error] myasp-membership.php:823
[myasp_login_error] myasp-membership.php:838
[myasp_login_error] myasp-membership.php:849
[myasp_password_error] myasp-membership.php:864
[myasp_password_error] myasp-membership.php:882
[myasp_password_error] myasp-membership.php:913
[myasp_password_error] myasp-membership.php:926
[myasp_reminder] myasp-membership.php:941
[myasp_password_error] myasp-membership.php:948
[myasp_password_error] myasp-membership.php:961
[myasp_login_error] myasp-membership.php:1116
[myasp_login_form] myasp-membership.php:1121
[myasp_login_error] myasp-membership.php:1158
[myasp_register_form_url_list] myasp-membership.php:1204
[myasp_password_error] myasp-membership.php:1208
[myasp_logout_url] myasp-membership.php:1213
[myasp_name] myasp-membership.php:1228
[myasp_name1] myasp-membership.php:1238
[myasp_name2] myasp-membership.php:1248
[myasp_mail] myasp-membership.php:1258
[myasp_register_form_url] myasp-membership.php:1267
[myasp_register_form_link] myasp-membership.php:1286
[myasp_register_form_tag] myasp-membership.php:1320
[myasp_ismember] myasp-membership.php:1336
[myasp_nonmember] myasp-membership.php:1346
[myasp_private_area] myasp-membership.php:1356
[!myasp_private_area] myasp-membership.php:1377
[myasp_tag_more_protection] myasp-membership.php:1393
[myasp_password] myasp-membership.php:1398
[myasp_change_password] myasp-membership.php:1407
[myasp_form_nonce] myasp-membership.php:1436
[myasp_general_error] myasp-membership.php:1451
WordPress Hooks 20
actioninitmyasp-membership.php:16
filterdo_redirect_guess_404_permalinkmyasp-membership.php:22
actionpre_get_postsmyasp-membership.php:36
filterquery_varsmyasp-membership.php:51
filterwp_kses_allowed_htmlmyasp-membership.php:61
actionrest_api_initmyasp-membership.php:140
actionadmin_menumyasp-membership.php:149
actionadmin_initmyasp-membership.php:152
actionadmin_noticesmyasp-membership.php:153
actionpost_tag_edit_form_fieldsmyasp-membership.php:161
actionedited_termmyasp-membership.php:163
filtermanage_edit-post_tag_columnsmyasp-membership.php:167
actionmanage_post_tag_custom_columnmyasp-membership.php:169
actionquick_edit_custom_boxmyasp-membership.php:173
actionadmin_enqueue_scriptsmyasp-membership.php:175
actionall_admin_noticesmyasp-membership.php:178
actionwp_enqueue_scriptsmyasp-membership.php:187
actiontemplate_redirectmyasp-membership.php:202
filterthe_contentmyasp-membership.php:207
filterwp_footermyasp-membership.php:893
Maintenance & Trust

MyASP MemberShip Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedJun 11, 2025
PHP min version7.3.33
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

MyASP MemberShip Developer Profile

myaspdev

1 plugin · 100 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect MyASP MemberShip

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/myasp-membership/client/css/myasp-paywall.css/wp-content/plugins/myasp-membership/client/js/myasp-client.js

HTML / DOM Fingerprints

CSS Classes
myasp_login_form
HTML Comments
<!-- wp:paragraph --><!-- /wp:paragraph --><!-- wp:shortcode --><!-- /wp:shortcode -->+4 more
Data Attributes
action
JS Globals
MyASPMembershipClient
REST Endpoints
/wp-json/myasp-membership-plugin/v1/items
Shortcode Output
[myasp_register_form_url_list][myasp_login_error]
FAQ

Frequently Asked Questions about MyASP MemberShip