RoleMaster Suite – User Role Editor for Ecommerce, Membership admin panel Security & Risk Analysis

wordpress.org/plugins/rolemaster-suite

Role Master Suite the best user role management and access control plugin. Create, modify, and assign capabilities, ideal for ecommerce and membership …

600 active installs v1.0.4 PHP 7.0+ WP 5.0+ Updated Mar 11, 2026
access-controleditormembershipuser-roleuser-role-editor
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is RoleMaster Suite – User Role Editor for Ecommerce, Membership admin panel Safe to Use in 2026?

Generally Safe

Score 100/100

RoleMaster Suite – User Role Editor for Ecommerce, Membership admin panel has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The Rolemaster Suite plugin v1.0.4 exhibits a generally strong security posture based on the provided static analysis. All identified AJAX handlers, the entire attack surface, are protected with nonce and capability checks, which is an excellent practice. The plugin also adheres to secure coding practices by exclusively using prepared statements for SQL queries and demonstrates a good effort in output escaping, with 76% of outputs properly escaped. The absence of known CVEs and historical vulnerabilities further strengthens this positive outlook, suggesting a well-maintained and security-conscious development process.

However, there are areas for improvement that temper the overall assessment. The presence of two taint analysis flows with unsanitized paths, even without critical or high severity, indicates a potential for subtle vulnerabilities if exploited in conjunction with other factors. While the absence of file operations and external HTTP requests is positive, the four external HTTP requests themselves warrant scrutiny to ensure they are being made securely and don't expose the application to risks. The 76% output escaping rate, while good, means that 24% of outputs are not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if untrusted data is displayed without sanitization.

In conclusion, Rolemaster Suite v1.0.4 is a relatively secure plugin with a strong foundation in authentication and secure query handling. The development team appears to prioritize security. The main concerns lie in the potential risks associated with unsanitized taint flows and incompletely escaped output, which, while not critical in this analysis, represent potential attack vectors. Addressing these areas through more comprehensive sanitization and ensuring 100% output escaping would further solidify the plugin's security.

Key Concerns

  • Taint flows with unsanitized paths
  • Unescaped output (24%)
  • External HTTP requests (4)
Vulnerabilities
None known

RoleMaster Suite – User Role Editor for Ecommerce, Membership admin panel Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

RoleMaster Suite – User Role Editor for Ecommerce, Membership admin panel Release Timeline

v1.0.4Current
v1.0.3
v1.0.2
v1.0.1.5
v1.0.1.4
v1.0.1.1
v1.0.1
Code Analysis
Analyzed Mar 16, 2026

RoleMaster Suite – User Role Editor for Ecommerce, Membership admin panel Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
49
152 escaped
Nonce Checks
6
Capability Checks
6
File Operations
0
External Requests
4
Bundled Libraries
0

Output Escaping

76% escaped201 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
notification_action (Inc\Classes\Notifications\Notifications.php:50)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

RoleMaster Suite – User Role Editor for Ecommerce, Membership admin panel Attack Surface

Entry Points6
Unprotected0

AJAX Handlers 6

authwp_ajax_rolemaster_suite_deactivation_surveyInc\Classes\Feedback.php:29
authwp_ajax_rolemaster_suite_notification_actionInc\Classes\Notifications\Notifications.php:42
authwp_ajax_rolemaster_suite_subscribeInc\Classes\Notifications\Subscribe.php:27
authwp_ajax_rolemaster_suite_allow_collectInc\Classes\Notifications\What_We_Collect.php:27
authwp_ajax_rolemaster_suite_recommended_upgrade_pluginLibs\Recommended.php:43
authwp_ajax_rolemaster_suite_recommended_activate_pluginLibs\Recommended.php:44
WordPress Hooks 25
actionplugins_loadedclass-rolemaster-suite.php:47
filteradmin_body_classclass-rolemaster-suite.php:49
actioninitclass-rolemaster-suite.php:156
actionadmin_enqueue_scriptsInc\Classes\Feedback.php:27
actionadmin_footerInc\Classes\Feedback.php:28
actionadmin_noticesInc\Classes\Notifications\Notifications.php:37
actionrolemaster_suite_display_noticeInc\Classes\Notifications\Notifications.php:39
actionrolemaster_suite_display_popupInc\Classes\Notifications\Notifications.php:40
actionrolemaster_suite_sheet_promo_data_resetInc\Classes\Notifications\Upgrade_Notice.php:26
actionadmin_footerInc\Classes\Pro_Upgrade.php:46
actioninitInc\Classes\UserRoleEditor.php:22
actionadmin_menuInc\Classes\UserRoleEditor.php:26
actionadmin_menuInc\Classes\UserRoleEditor.php:28
filteradmin_body_classInc\Classes\UserRoleEditor.php:31
filteradmin_initInc\Classes\UserRoleEditor.php:32
filterregister_post_type_argsInc\Classes\UserRoleEditor.php:33
filterdoing_it_wrong_trigger_errorInc\Classes\UserRoleEditor.php:37
filtermap_meta_capInc\Classes\UserRoleEditor.php:40
actionrest_api_initInc\Classes\UserRoleEditorApiEndPoints.php:16
actionadmin_enqueue_scriptsInc\Classes\UserRoleEditorAssets.php:19
actionwp_enqueue_scriptsLibs\Assets.php:25
actionadmin_enqueue_scriptsLibs\Assets.php:26
filterinstall_plugins_table_api_args_featuredLibs\Featured.php:23
filterplugins_api_resultLibs\Featured.php:33
actionadmin_menuLibs\Recommended.php:42
Maintenance & Trust

RoleMaster Suite – User Role Editor for Ecommerce, Membership admin panel Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 11, 2026
PHP min version7.0
Downloads7K

Community Trust

Rating74/100
Number of ratings3
Active installs600
Developer Profile

RoleMaster Suite – User Role Editor for Ecommerce, Membership admin panel Developer Profile

Liton Arefin

49 plugins · 43K total installs

82
trust score
Avg Security Score
91/100
Avg Patch Time
63 days
View full developer profile
Detection Fingerprints

How We Detect RoleMaster Suite – User Role Editor for Ecommerce, Membership admin panel

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/rolemaster-suite/assets/css/rolemaster-suite-survey.css

HTML / DOM Fingerprints

CSS Classes
rolemaster-suite-deactivate-survey-overlayrolemaster-suite-deactivate-survey-modalrolemaster-suite-deactivate-survey-headerrolemaster-suite-deactivate-inforolemaster-suite-deactivate-content-wrapperrolemaster-suite-deactivate-form-wrapperrolemaster-suite-deactivate-input-wrapperrolemaster-suite-deactivate-feedback-input+1 more
Data Attributes
id="rolemaster-suite-deactivate-survey-overlay"id="rolemaster-suite-deactivate-survey-modal"id="rolemaster-suite-deactivate-feedback-no-longer-needed"id="rolemaster-suite-deactivate-feedback-found-a-better-plugin"id="rolemaster-suite-deactivate-feedback-couldnt-get-the-plugin-to-work"id="rolemaster-suite-deactivate-feedback-temporary-deactivation"+3 more
REST Endpoints
/wp-json/rolemaster-suite/v1/deactivation-survey
FAQ

Frequently Asked Questions about RoleMaster Suite – User Role Editor for Ecommerce, Membership admin panel