
NewPath WildApricotPress Add-on – Member Directory Security & Risk Analysis
wordpress.org/plugins/newpath-wildapricotpress-add-on-member-directoryNewPath WildApricotPress Add-on – Member Directory enables WordPress websites to render native WildApricot member directories and member profiles, wit …
Is NewPath WildApricotPress Add-on – Member Directory Safe to Use in 2026?
Generally Safe
Score 100/100NewPath WildApricotPress Add-on – Member Directory has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "newpath-wildapricotpress-add-on-member-directory" plugin v1.0.0 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by using prepared statements for all SQL queries and properly escaping all output, which significantly mitigates common injection and cross-site scripting vulnerabilities. There are no recorded vulnerabilities (CVEs) or dangerous function usage, indicating a history of diligent security practices.
However, there are significant concerns regarding the plugin's attack surface. A substantial portion of its entry points, specifically 4 out of 5, lack authentication checks. This includes all 4 REST API routes and the single AJAX handler. This oversight presents a high risk of unauthorized access and potential manipulation of plugin functionality by unauthenticated users. The absence of nonce checks on AJAX handlers further exacerbates this risk, making it easier for attackers to craft malicious requests. The lack of capability checks on REST API routes is also a serious concern, allowing any user, even those with minimal privileges, to interact with these endpoints.
While the plugin has a clean vulnerability history, the extensive unprotected entry points are a critical weakness that overshadows its strengths. The lack of taint analysis results might be due to the limited complexity or scope of the analyzed code, but the clear presence of unprotected endpoints is a direct and actionable security concern. It is strongly recommended to implement robust authentication and authorization checks on all exposed entry points before deployment.
Key Concerns
- Unprotected REST API routes
- Unprotected AJAX handler
- Missing nonce checks on AJAX
- Missing capability checks
NewPath WildApricotPress Add-on – Member Directory Security Vulnerabilities
NewPath WildApricotPress Add-on – Member Directory Code Analysis
SQL Query Safety
Output Escaping
NewPath WildApricotPress Add-on – Member Directory Attack Surface
REST API Routes 4
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
NewPath WildApricotPress Add-on – Member Directory Maintenance & Trust
Maintenance Signals
Community Trust
NewPath WildApricotPress Add-on – Member Directory Alternatives
NewPath WildApricot Press
newpath-wildapricot-press
NewPath WildApricot Press enables WordPress websites to support the WildApricot membership management system.
NewPath WildApricotPress Add-on – iFrame Widget
newpath-wildapricotpress-add-on-iframe-widget
The iFrame Widget block enables NewPath WildApricot Press customers to insert WildApricot iframe widgets into a post or page without needing to know t …
Wild Apricot Login
wild-apricot-login
Provides single sign-on service for Wild Apricot members to provide access to restricted Wild Apricot content.
Members – Membership & User Role Editor Plugin
members
The best WordPress membership and user role editor plugin. User Roles & Capabilities editor helps you restrict content in just a few clicks.
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
ultimate-member
Membership & community plugin with user profiles, registration & login, member directories, content restriction, user roles and much more.
NewPath WildApricotPress Add-on – Member Directory Developer Profile
3 plugins · 100 total installs
How We Detect NewPath WildApricotPress Add-on – Member Directory
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/newpath-wildapricotpress-add-on-member-directory/js/wafw.js/wp-content/plugins/newpath-wildapricotpress-add-on-member-directory/js/pagination.js/wp-content/plugins/newpath-wildapricotpress-add-on-member-directory/js/pagination.min.js/wp-content/plugins/newpath-wildapricotpress-add-on-member-directory/js/profiles.js/wp-content/plugins/newpath-wildapricotpress-add-on-member-directory/blocks/member-directory/wp-content/plugins/newpath-wildapricotpress-add-on-member-directory/blocks/member-profileHTML / DOM Fingerprints
wa-contactsdata-search-iddata-profile-urlwindow.WAWP_MEMDIR_SLUG/wafw/v1/contacts/search//wawp/v1/contacts/fields//wawp/v1/savedsearches//wawp/v1/profiles/[wa-contacts]