Lock Down ( Privacy ) for Ultimate Member Security & Risk Analysis

wordpress.org/plugins/um-lock-down

A plugin for Ultimate member that allows users to completely lock down their account

10 active installs v1.0.1 PHP 5.6+ WP 3.0.1+ Updated Apr 27, 2019
ultimate-memberultimate-member-lock-downultimate-member-privacyultimatememberum-lock-down
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Lock Down ( Privacy ) for Ultimate Member Safe to Use in 2026?

Generally Safe

Score 85/100

Lock Down ( Privacy ) for Ultimate Member has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The um-lock-down plugin v1.0.1 demonstrates a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, unsanitized taint flows, or SQL queries utilizing prepared statements are excellent indicators of secure coding practices. Furthermore, the plugin correctly escapes all identified output, and there are no file operations or external HTTP requests, which further limits potential attack vectors. The vulnerability history being completely clear of any known CVEs suggests a history of responsible development and maintenance.

However, the static analysis does reveal some areas for improvement. The complete absence of nonce checks and capability checks across all entry points is a significant concern. While the attack surface is currently zero, this lack of authorization checks means that if any new entry points were introduced in the future, they would be immediately unprotected, posing a serious security risk. This indicates a potential over-reliance on the current limited attack surface rather than proactive security measures.

In conclusion, the plugin exhibits robust core security features, particularly in its handling of data and SQL. Its clean vulnerability history is a testament to this. The primary weakness lies in the foundational security controls around access management. While the current state is secure due to a lack of exposed entry points, the absence of nonce and capability checks represents a latent risk that should be addressed for future development.

Key Concerns

  • Missing nonce checks on entry points
  • Missing capability checks on entry points
Vulnerabilities
None known

Lock Down ( Privacy ) for Ultimate Member Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Lock Down ( Privacy ) for Ultimate Member Release Timeline

v1.0.1Current
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

Lock Down ( Privacy ) for Ultimate Member Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
0
10 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

100% escaped10 total outputs
Attack Surface

Lock Down ( Privacy ) for Ultimate Member Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
filterum_account_tab_privacy_fieldsincludes/class-core.php:42
filterum_predefined_fields_hookincludes/class-core.php:43
filterum_shortcode_args_filterincludes/class-core.php:44
actionum_before_profile_form_is_loadedincludes/class-core.php:45
filterum_prepare_user_query_argsincludes/class-core.php:46
filterum_settings_structureincludes/class-core.php:47
actioninitum-lock-down.php:168
actionall_admin_noticesum-lock-down.php:231
actionadmin_initum-lock-down.php:234
actionplugins_loadedum-lock-down.php:375
Maintenance & Trust

Lock Down ( Privacy ) for Ultimate Member Maintenance & Trust

Maintenance Signals

WordPress version tested5.1.22
Last updatedApr 27, 2019
PHP min version5.6
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Lock Down ( Privacy ) for Ultimate Member Developer Profile

SuitePlugins

19 plugins · 2K total installs

90
trust score
Avg Security Score
85/100
Avg Patch Time
7 days
View full developer profile
Detection Fingerprints

How We Detect Lock Down ( Privacy ) for Ultimate Member

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/um-lock-down/assets/css/um-lock-down-admin.css/wp-content/plugins/um-lock-down/assets/js/um-lock-down-admin.js
Script Paths
/wp-content/plugins/um-lock-down/assets/js/um-lock-down-admin.js
Version Parameters
um-lock-down/assets/css/um-lock-down-admin.css?ver=um-lock-down/assets/js/um-lock-down-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
umld-admin-notice
HTML Comments
Copyright (c) 2019 SuitePlugins (email : info@suiteplugins.com)This program is free software; you can redistribute it and/or modifyit under the terms of the GNU General Public License, version 2 or, atyour discretion, any later version, as published by the Free+9 more
FAQ

Frequently Asked Questions about Lock Down ( Privacy ) for Ultimate Member