Simple ActiveCampaign Membership DigitalME Security & Risk Analysis

wordpress.org/plugins/simple-activecampaign-membership-digitalme

Allow or disallow a specific ActiveCampaign tag to either show or not show a page

0 active installs v1.3.7 PHP 7.0+ WP 4.7+ Updated Nov 28, 2025
activecampaigncrmemailmarketingmembershipsubscription
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Simple ActiveCampaign Membership DigitalME Safe to Use in 2026?

Generally Safe

Score 100/100

Simple ActiveCampaign Membership DigitalME has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The security posture of the 'simple-activecampaign-membership-digitalme' plugin v1.3.7 appears to be generally good, with several positive indicators. The plugin makes no direct use of dangerous functions and all SQL queries are properly prepared, mitigating common SQL injection risks. Additionally, the presence of nonce and capability checks on its entry points suggests an effort to secure these functions against unauthorized access. The plugin's vulnerability history is also a strong positive, with no known CVEs recorded, implying a stable and likely well-maintained codebase.

However, there are a few areas that warrant attention. The static analysis revealed a flow with an unsanitized path in the taint analysis, which, while not classified as critical or high severity, represents a potential risk if that path can be influenced by user input. Furthermore, a significant portion of output escaping (27%) is not properly handled, which could lead to cross-site scripting (XSS) vulnerabilities, especially if sensitive data is displayed without adequate sanitization. The plugin also makes 10 external HTTP requests, which can sometimes introduce supply chain risks if the target endpoints are compromised or if these requests are not handled securely.

In conclusion, while the plugin demonstrates good security practices in key areas like SQL and access control, the presence of an unsanitized path and incomplete output escaping are potential weaknesses. The clean vulnerability history is a strong indicator of the developer's diligence. Addressing the output escaping and carefully reviewing the unsanitized path flow would further strengthen the plugin's security.

Key Concerns

  • Flows with unsanitized paths
  • Unescaped output (27% of total)
Vulnerabilities
None known

Simple ActiveCampaign Membership DigitalME Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Simple ActiveCampaign Membership DigitalME Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
3
8 escaped
Nonce Checks
2
Capability Checks
3
File Operations
1
External Requests
10
Bundled Libraries
0

SQL Query Safety

100% prepared4 total queries

Output Escaping

73% escaped11 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
sacd_license_management_page (simple-activecampaign-membership-digitalme.php:530)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Simple ActiveCampaign Membership DigitalME Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_sacd_get_ac_formssimple-activecampaign-membership-digitalme.php:220
authwp_ajax_sacd_get_ac_tagssimple-activecampaign-membership-digitalme.php:241
WordPress Hooks 14
actioninitclass-sacd.php:9
filterwoocommerce_checkout_get_valueclass-sacd.php:10
actionenqueue_block_editor_assetsclass-sacd.php:11
actionadmin_enqueue_scriptsclass-sacd.php:12
actionadmin_menusettings-page.php:24
actionadmin_initsettings-page.php:88
actionadmin_initsimple-activecampaign-membership-digitalme.php:59
actionwp_enqueue_scriptssimple-activecampaign-membership-digitalme.php:150
actioninitsimple-activecampaign-membership-digitalme.php:200
actiontemplate_redirectsimple-activecampaign-membership-digitalme.php:421
filterthe_contentsimple-activecampaign-membership-digitalme.php:490
actionadmin_noticessimple-activecampaign-membership-digitalme.php:505
actionadmin_menusimple-activecampaign-membership-digitalme.php:528
actioninitsimple-activecampaign-membership-digitalme.php:614
Maintenance & Trust

Simple ActiveCampaign Membership DigitalME Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 28, 2025
PHP min version7.0
Downloads311

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Simple ActiveCampaign Membership DigitalME Developer Profile

DigitalME

20 plugins · 140K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
3200 days
View full developer profile
Detection Fingerprints

How We Detect Simple ActiveCampaign Membership DigitalME

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/simple-activecampaign-membership-digitalme/js/script.js/wp-content/plugins/simple-activecampaign-membership-digitalme/js/block.js
Script Paths
/wp-content/plugins/simple-activecampaign-membership-digitalme/js/script.js/wp-content/plugins/simple-activecampaign-membership-digitalme/js/block.js

HTML / DOM Fingerprints

CSS Classes
sacd-logs-wrapwp-list-tablesacd
Data Attributes
data-sacd-tag-iddata-sacd-disallowed-tag-iddata-sacd-fallback-url
JS Globals
sacd
REST Endpoints
/wp-json/wp/v2/posts/wp-json/wp/v2/pages
FAQ

Frequently Asked Questions about Simple ActiveCampaign Membership DigitalME