Stories for Ultimate Member Security & Risk Analysis

wordpress.org/plugins/um-story-lite

Easy to use Frontend Journal for Ultimate Member. Give your users the option to add posts from the frontend

20 active installs v1.0.2.2 PHP 5.6+ WP 3.0.1+ Updated May 21, 2023
front-end-postultimate-memberultimate-member-frontendultimatememberultimatemember-stories
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Stories for Ultimate Member Safe to Use in 2026?

Generally Safe

Score 85/100

Stories for Ultimate Member has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The security posture of um-story-lite v1.0.2.2 appears to be relatively strong based on the provided static analysis. The plugin exhibits good practices by having zero unprotected entry points and utilizing prepared statements for its single SQL query. The absence of dangerous functions, file operations, and external HTTP requests further reduces its attack surface. The presence of nonce checks is also a positive indicator. However, a notable concern is the lack of capability checks on any entry points. While the static analysis did not reveal any exploitable taint flows or known vulnerabilities, the absence of capability checks means that any potential future vulnerability introduced could be more easily exploited by unauthenticated users if not properly mitigated in development.

Key Concerns

  • No capability checks found
  • Output escaping not fully implemented (70% proper)
Vulnerabilities
None known

Stories for Ultimate Member Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Stories for Ultimate Member Release Timeline

v1.0.2.2Current
v1.0.2.1
v1.0.1
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

Stories for Ultimate Member Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
16
38 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

70% escaped54 total outputs
Attack Surface

Stories for Ultimate Member Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 13
actioninitincludes/class-core.php:44
filterum_profile_tabsincludes/class-template.php:43
actionum_story_form_contentincludes/class-template.php:53
actionum_story_form_contentincludes/class-template.php:54
actionum_story_form_contentincludes/class-template.php:55
actionum_story_form_contentincludes/class-template.php:56
actiontemplate_redirectincludes/class-template.php:58
filterthe_contentincludes/class-template.php:239
actioninitum-story-lite.php:184
actionwp_enqueue_scriptsum-story-lite.php:185
actionall_admin_noticesum-story-lite.php:278
actionadmin_initum-story-lite.php:281
actionplugins_loadedum-story-lite.php:443
Maintenance & Trust

Stories for Ultimate Member Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedMay 21, 2023
PHP min version5.6
Downloads3K

Community Trust

Rating20/100
Number of ratings1
Active installs20
Developer Profile

Stories for Ultimate Member Developer Profile

SuitePlugins

19 plugins · 2K total installs

90
trust score
Avg Security Score
85/100
Avg Patch Time
7 days
View full developer profile
Detection Fingerprints

How We Detect Stories for Ultimate Member

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/um-story-lite/assets/css/um-story.css/wp-content/plugins/um-story-lite/assets/css/um-story.min.css/wp-content/plugins/um-story-lite/assets/js/um-story.js/wp-content/plugins/um-story-lite/assets/js/um-story.min.js
Version Parameters
um-story-lite/assets/css/um-story.css?ver=um-story-lite/assets/js/um-story.js?ver=

HTML / DOM Fingerprints

JS Globals
UMSL_CoreUMSL_Template
FAQ

Frequently Asked Questions about Stories for Ultimate Member