
Simple Membership After Login Redirection Security & Risk Analysis
wordpress.org/plugins/simple-membership-after-login-redirectionAn addon for the simple membership plugin to configure after login redirection to a specific page based on the member's level.
Is Simple Membership After Login Redirection Safe to Use in 2026?
Generally Safe
Score 99/100Simple Membership After Login Redirection has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of 'simple-membership-after-login-redirection' v2.0 indicates a generally good security posture with no identified dangerous functions, SQL queries using prepared statements, or unescaped output. There are also no external HTTP requests or file operations, further reducing the attack surface. However, the absence of any nonce or capability checks on entry points is a significant concern, as it means all requests to the plugin's functionality are unprotected by default.
The taint analysis revealed two flows with unsanitized paths, which, while not flagged as critical or high severity, represent a potential risk if these paths are user-controllable. The vulnerability history shows one known CVE for 'Open Redirect', and although it is currently patched, it highlights a recurring vulnerability type that requires vigilance. The plugin's lack of explicit authentication checks on its entry points, combined with the history of redirection vulnerabilities, suggests a need for more robust access control mechanisms.
In conclusion, while the plugin employs sound practices regarding SQL and output handling, the lack of authentication and authorization on its entry points is a primary weakness. The past 'Open Redirect' vulnerability, even if patched, should serve as a reminder to carefully review all user-inputted data that influences redirects. Addressing the unsanitized paths in the taint analysis and implementing proper capability checks on entry points would significantly enhance the plugin's security.
Key Concerns
- No capability checks on entry points
- No nonce checks on entry points
- Taint flows with unsanitized paths
- Known CVE history (Open Redirect)
Simple Membership After Login Redirection Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Simple Membership After Login Redirection <= 1.6 - Open Redirect
Simple Membership After Login Redirection Code Analysis
Output Escaping
Data Flow Analysis
Simple Membership After Login Redirection Attack Surface
WordPress Hooks 15
Maintenance & Trust
Simple Membership After Login Redirection Maintenance & Trust
Maintenance Signals
Community Trust
Simple Membership After Login Redirection Alternatives
WP-Members Membership Plugin
wp-members
The original WordPress membership plugin with content restriction, user login, custom registration fields, user profiles, and more.
WP Login Form
wp-login-form
Create a WordPress login form and add it to your post, page or sidebar
Expire User Passwords
expire-user-passwords
Require certain users to change their passwords on a regular basis.
Pie Register – User Registration, Profiles & Content Restriction
pie-register
Create customized registration forms, Invite through email, Email Notification, User Roles assignment, and more. Pie Register is a User Registration p …
Prevent Concurrent Logins
prevent-concurrent-logins
Prevents users from staying logged into the same account from multiple places.
Simple Membership After Login Redirection Developer Profile
14 plugins · 76K total installs
How We Detect Simple Membership After Login Redirection
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
simple-membership-after-login-redirection/includes/js/custom_script.js?ver=simple-membership-after-login-redirection/includes/css/custom_style.css?ver=HTML / DOM Fingerprints
name="custom[swpm_alr_after_login_page_field]"