
Ultimate Member Jogging Platform Security & Risk Analysis
wordpress.org/plugins/um-jogging-platformSocial jogging platform which is an extension of the Ultimate member plugin. The users can track their progress and compete with each other for variou …
Is Ultimate Member Jogging Platform Safe to Use in 2026?
Generally Safe
Score 85/100Ultimate Member Jogging Platform has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "um-jogging-platform" plugin v1.0.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices in its handling of SQL queries, with a very high percentage using prepared statements, and a solid output escaping rate. The absence of known vulnerabilities in its history and no critical or high severity taint flows are also positive indicators.
However, there are significant concerns that mitigate the overall security. The plugin has a single unprotected AJAX handler, which represents a direct attack vector. The complete lack of nonce checks on AJAX requests exacerbates this risk, making it susceptible to Cross-Site Request Forgery (CSRF) attacks. Furthermore, while the plugin uses capability checks, only one is present, and the overall number of entry points is low but one remains vulnerable. The presence of file operations without explicit context on their sanitization also warrants caution.
In conclusion, while the plugin has a clean vulnerability history and uses secure coding practices for SQL and output, the unprotected AJAX handler and missing nonce checks are critical security flaws. These vulnerabilities, if exploited, could lead to unauthorized actions on behalf of logged-in users. The plugin's overall security can be significantly improved by addressing these specific entry point vulnerabilities.
Key Concerns
- Unprotected AJAX handler
- Missing nonce checks on AJAX
- Low number of capability checks
- File operations without context
Ultimate Member Jogging Platform Security Vulnerabilities
Ultimate Member Jogging Platform Release Timeline
Ultimate Member Jogging Platform Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Ultimate Member Jogging Platform Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 12
Scheduled Events 1
Maintenance & Trust
Ultimate Member Jogging Platform Maintenance & Trust
Maintenance Signals
Community Trust
Ultimate Member Jogging Platform Alternatives
Social Media Links for Ultimate Member
social-media-links-for-ultimate-member
Adds social media accounts to Ultimate Member profile
QuantiModo
quantimodo
QuantiModo WordPress Integration Help ignite a revolution of citizen science to find new solutions to chronic illnesses. Install the Quantimodo Word …
Ultimate Member – Post Status
ultimate-member-post-status
Adds a shortcode to Ultimate Member that creates a button for a status update modal like Twitter.
AddToAny Share Buttons
add-to-any
Share buttons for WordPress including the AddToAny button, Facebook, Bluesky, Mastodon, WhatsApp, Pinterest, Reddit, many more, and follow icons too.
Health Check & Troubleshooting
health-check
Health Check identifies common problems, and helps you troubleshoot plugin and theme conflicts.
Ultimate Member Jogging Platform Developer Profile
1 plugin · 10 total installs
How We Detect Ultimate Member Jogging Platform
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/um-jogging-platform/assets/css/enter-data.css/wp-content/plugins/um-jogging-platform/assets/css/umjp-advice.css/wp-content/plugins/um-jogging-platform/assets/css/umjp-advice-output.cssHTML / DOM Fingerprints
umjp-advice-templateumjp-advice-output-templateumjp-account-template