
ExpressTechSoftwares Discord Add-on for Paid Memberships Pro Security & Risk Analysis
wordpress.org/plugins/pmpro-discord-add-onThis add-on enables connecting your PMPro enabled website to your discord server. Now you can add/remove PMPro members directly to your discord server …
Is ExpressTechSoftwares Discord Add-on for Paid Memberships Pro Safe to Use in 2026?
Generally Safe
Score 100/100ExpressTechSoftwares Discord Add-on for Paid Memberships Pro has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "pmpro-discord-add-on" v2.0.1 demonstrates a generally good security posture with a robust implementation of security checks. The absence of any recorded vulnerabilities or CVEs, combined with a comprehensive use of nonce and capability checks across all identified entry points (AJAX handlers, shortcodes, cron events), indicates a proactive approach to security by the developers. The high percentage of SQL queries utilizing prepared statements further strengthens this assessment.
However, the static analysis reveals a significant concern regarding the presence of the `unserialize()` function, which is a known attack vector if used with untrusted user input. While the current taint analysis doesn't indicate critical or high severity flows stemming from this, the potential for exploitation exists. The taint analysis did identify one flow with an unsanitized path, which warrants further investigation to ensure no vulnerabilities are present. The moderate percentage of properly escaped outputs also suggests a small risk of cross-site scripting (XSS) vulnerabilities if certain dynamic content is not handled with sufficient care.
In conclusion, the plugin exhibits strong security foundations, particularly in its handling of entry points and data integrity with prepared statements. The vulnerability history is a significant positive indicator. The primary areas for improvement and vigilance are the use of `unserialize()` and the single unsanitized path identified in the taint analysis, which, although not currently flagged as critical, represent potential risks that should be mitigated.
Key Concerns
- Presence of unserialize() function
- Flow with unsanitized path identified
- Only 67% of outputs properly escaped
ExpressTechSoftwares Discord Add-on for Paid Memberships Pro Security Vulnerabilities
ExpressTechSoftwares Discord Add-on for Paid Memberships Pro Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
ExpressTechSoftwares Discord Add-on for Paid Memberships Pro Attack Surface
AJAX Handlers 5
Shortcodes 2
WordPress Hooks 39
Scheduled Events 1
Maintenance & Trust
ExpressTechSoftwares Discord Add-on for Paid Memberships Pro Maintenance & Trust
Maintenance Signals
Community Trust
ExpressTechSoftwares Discord Add-on for Paid Memberships Pro Alternatives
Connect LearnDash to Discord
connect-learndash-and-discord
Create a community of your students by connecting your LearnDash Website to your Discord server.
Connect Tutor LMS to Discord
connect-tutorlms-to-discord
Create a community of your students by connecting your TUTOR LMS Website to your Discord server.
Connect LearnPress to Discord
connect-learnpress-discord-add-on
Create a community of your students by connecting your LearnPress Website to your Discord server.
Connect LifterLMS to Discord
connect-lifterlms-to-discord
Create a community of your students by connecting your LifterLMS Website to your Discord server.
Connect Restrict Content Pro to Discord AddOn
connect-restrictcontentpro-to-discord-addon
This add-on enables connecting your Restrict Content enabled website to your discord server. Now you can add/remove RCP customers directly to your dis …
ExpressTechSoftwares Discord Add-on for Paid Memberships Pro Developer Profile
14 plugins · 2K total installs
How We Detect ExpressTechSoftwares Discord Add-on for Paid Memberships Pro
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pmpro-discord-add-on/includes/js/admin.js/wp-content/plugins/pmpro-discord-add-on/includes/js/front.js/wp-content/plugins/pmpro-discord-add-on/includes/css/admin.css/wp-content/plugins/pmpro-discord-add-on/includes/css/front.css/wp-content/plugins/pmpro-discord-add-on/includes/js/admin.js/wp-content/plugins/pmpro-discord-add-on/includes/js/front.jspmpro-discord-add-on/includes/js/admin.js?ver=pmpro-discord-add-on/includes/js/front.js?ver=pmpro-discord-add-on/includes/css/admin.css?ver=pmpro-discord-add-on/includes/css/front.css?ver=HTML / DOM Fingerprints
ets-pmpro-discord-buttondata-discord-logged-out-textdata-discord-logged-in-textdata-discord-disconnect-textdata-discord-btn-colordata-discord-btn-disconnect-colordata-discord-allow-none-memberets_pmpro_discord_vars[discord_connect_button][discord_user_info]