Orbisius Member Only Downloads for S2Member Security & Risk Analysis

wordpress.org/plugins/orbisius-member-only-downloads-for-s2member

Support

10 active installs v1.0.2 PHP + WP 3.0+ Updated Unknown
downloaddownloadsorbisiuswp
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Orbisius Member Only Downloads for S2Member Safe to Use in 2026?

Generally Safe

Score 100/100

Orbisius Member Only Downloads for S2Member has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The plugin "orbisius-member-only-downloads-for-s2member" v1.0.2 exhibits a generally good security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and no critical or high severity vulnerabilities in its history is a strong indicator of a well-maintained and secure plugin. The code analysis also reveals positive security practices such as 100% of SQL queries using prepared statements and a reasonable number of capability checks for its entry points. However, there are areas that warrant attention and could be improved. The low percentage of properly escaped output (7%) is a significant concern, as this could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is directly reflected in the output without proper sanitization. While no taint flows with unsanitized paths were detected, the low output escaping percentage suggests that such issues could easily arise. Furthermore, the lack of nonce checks, while not explicitly flagged as a vulnerability in this analysis, is a common security best practice that is missing. The plugin's attack surface is minimal, with only one shortcode and no unprotected entry points identified, which is a positive aspect. Overall, the plugin is likely secure against known external threats due to its clean vulnerability history, but the insufficient output escaping presents an internal risk that should be addressed.

Key Concerns

  • Low output escaping percentage (7%)
  • Missing nonce checks
Vulnerabilities
None known

Orbisius Member Only Downloads for S2Member Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Orbisius Member Only Downloads for S2Member Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
38
3 escaped
Nonce Checks
0
Capability Checks
1
File Operations
4
External Requests
0
Bundled Libraries
0

Output Escaping

7% escaped41 total outputs
Attack Surface

Orbisius Member Only Downloads for S2Member Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[orb_s2member_dl] orbisius-s2member-only-downloads.php:94
WordPress Hooks 5
actioninitorbisius-s2member-only-downloads.php:29
actionadmin_initorbisius-s2member-only-downloads.php:30
actionadmin_menuorbisius-s2member-only-downloads.php:31
actionwp_footerorbisius-s2member-only-downloads.php:32
filterplugin_action_linksorbisius-s2member-only-downloads.php:120
Maintenance & Trust

Orbisius Member Only Downloads for S2Member Maintenance & Trust

Maintenance Signals

WordPress version tested4.1.42
Last updatedUnknown
PHP min version
Downloads3K

Community Trust

Rating20/100
Number of ratings1
Active installs10
Developer Profile

Orbisius Member Only Downloads for S2Member Developer Profile

Svetoslav Marinov

26 plugins · 12K total installs

71
trust score
Avg Security Score
88/100
Avg Patch Time
722 days
View full developer profile
Detection Fingerprints

How We Detect Orbisius Member Only Downloads for S2Member

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/orbisius-member-only-downloads-for-s2member/assets/main.css

HTML / DOM Fingerprints

CSS Classes
orbisius_s2member_downloads_only_containerorbisius_s2member_only_downloads_formorb-s2member-dl-positiveorb-s2member-dl-negative
HTML Comments
Copyright 2012 Svetoslav Marinov (Slavi) <slavi@orbisius.com>Set up plugin Replaces [orb_s2member_dl] with a download link. Requires user to be logged inAlso searches tags+11 more
Data Attributes
data-action="orbisius_s2member_only_downloads_nonce"
Shortcode Output
[orb_s2member_dl url="[orb_s2member_dl req_login=1 url="[orb_s2member_dl level=1 url="
FAQ

Frequently Asked Questions about Orbisius Member Only Downloads for S2Member