
Orbisius Member Only Downloads for S2Member Security & Risk Analysis
wordpress.org/plugins/orbisius-member-only-downloads-for-s2memberSupport
Is Orbisius Member Only Downloads for S2Member Safe to Use in 2026?
Generally Safe
Score 100/100Orbisius Member Only Downloads for S2Member has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "orbisius-member-only-downloads-for-s2member" v1.0.2 exhibits a generally good security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and no critical or high severity vulnerabilities in its history is a strong indicator of a well-maintained and secure plugin. The code analysis also reveals positive security practices such as 100% of SQL queries using prepared statements and a reasonable number of capability checks for its entry points. However, there are areas that warrant attention and could be improved. The low percentage of properly escaped output (7%) is a significant concern, as this could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is directly reflected in the output without proper sanitization. While no taint flows with unsanitized paths were detected, the low output escaping percentage suggests that such issues could easily arise. Furthermore, the lack of nonce checks, while not explicitly flagged as a vulnerability in this analysis, is a common security best practice that is missing. The plugin's attack surface is minimal, with only one shortcode and no unprotected entry points identified, which is a positive aspect. Overall, the plugin is likely secure against known external threats due to its clean vulnerability history, but the insufficient output escaping presents an internal risk that should be addressed.
Key Concerns
- Low output escaping percentage (7%)
- Missing nonce checks
Orbisius Member Only Downloads for S2Member Security Vulnerabilities
Orbisius Member Only Downloads for S2Member Code Analysis
Output Escaping
Orbisius Member Only Downloads for S2Member Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
Orbisius Member Only Downloads for S2Member Maintenance & Trust
Maintenance Signals
Community Trust
Orbisius Member Only Downloads for S2Member Alternatives
AffiliateWP – Affiliate Product Rates
affiliatewp-affiliate-product-rates
Allows you to set product referral rates on a per-affiliate level in AffiliateWP.
AffiliateWP – Allowed Products
affiliatewp-allowed-products
Allows only specific products to generate commission in AffiliateWP.
Tabbed Account Area for Easy Digital Downloads
tabbed-account-area-for-easy-digital-downloads
Shortcode to create tabbed account area for Easy Digital Downloads and AffiliateWP
WP-Stateless – Easy Digital Downloads Addon
wp-stateless-easy-digital-downloads-addon
Provides compatibility between the Easy Digital Downloads and the WP-Stateless plugins.
File Manager Pro – Filester
filester
Advanced File Manager and Code Editor. Best WordPress file manager without FTP access. No need to upgrade because this is PRO version.
Orbisius Member Only Downloads for S2Member Developer Profile
26 plugins · 12K total installs
How We Detect Orbisius Member Only Downloads for S2Member
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/orbisius-member-only-downloads-for-s2member/assets/main.cssHTML / DOM Fingerprints
orbisius_s2member_downloads_only_containerorbisius_s2member_only_downloads_formorb-s2member-dl-positiveorb-s2member-dl-negativeCopyright 2012 Svetoslav Marinov (Slavi) <slavi@orbisius.com>Set up plugin Replaces [orb_s2member_dl] with a download link. Requires user to be logged inAlso searches tags+11 moredata-action="orbisius_s2member_only_downloads_nonce"[orb_s2member_dl url="[orb_s2member_dl req_login=1 url="[orb_s2member_dl level=1 url="