
User List for Ultimate Member Security & Risk Analysis
wordpress.org/plugins/um-user-listA plugin for Ultimate member that allows users to display user suggestions in a simple widget.
Is User List for Ultimate Member Safe to Use in 2026?
Generally Safe
Score 85/100User List for Ultimate Member has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "um-user-list" plugin version 1.0.1.4 exhibits a mixed security posture. While it demonstrates good practices by avoiding dangerous functions, file operations, and external HTTP requests, and shows a commitment to prepared statements for most SQL queries, significant concerns are raised by the lack of security checks on its entry points. Specifically, the plugin has two AJAX handlers that lack authentication checks, creating a direct path for unauthenticated users to interact with potentially sensitive functionality. Furthermore, the complete absence of nonce and capability checks across the board is a critical oversight, as it means any user, regardless of their role or logged-in status, could trigger actions within these AJAX handlers. The plugin's vulnerability history is clean, with no recorded CVEs. This absence of past vulnerabilities is a positive indicator, suggesting a diligent development approach or simply a lack of exposure. However, this historical strength is overshadowed by the evident weaknesses in the current static analysis. In conclusion, while the plugin avoids common pitfalls like outdated bundled libraries or raw SQL queries, the unprotected AJAX endpoints represent a substantial risk that needs immediate attention.
Key Concerns
- AJAX handlers without auth checks
- AJAX handlers without capability checks
- No nonce checks on AJAX handlers
- 2 unprotected entry points
- Output escaping 78% (some unescaped)
User List for Ultimate Member Security Vulnerabilities
User List for Ultimate Member Code Analysis
SQL Query Safety
Output Escaping
User List for Ultimate Member Attack Surface
AJAX Handlers 2
Shortcodes 2
WordPress Hooks 8
Maintenance & Trust
User List for Ultimate Member Maintenance & Trust
Maintenance Signals
Community Trust
User List for Ultimate Member Alternatives
Login Widget for Ultimate Member
login-widget-for-ultimate-member
Easily add a login widget that works with Ultimate Member
Ultimate Member Custom Tab Builder Lite
um-custom-tab-builder-lite
An easy way to add custom profile tabs to Ultimate Member Profile. Ultimate Member 2.0 compatible
Video & Photo Gallery for Ultimate Member
gallery-for-ultimate-member
Enhance Ultimate Member with a Photo/Video Gallery Addon: Easy media sharing & vibrant community engagement."
UM Events
um-events-lite-for-ultimate-member
Easy to use Events Uploader for Ultimate Member. Give your users the option to create events
UM Navigation Menu
um-navigation-menu
An easy way to add Ultimate Member navigation to admin bar. Ultimate Member 2.0 compatible
User List for Ultimate Member Developer Profile
17 plugins · 2K total installs
How We Detect User List for Ultimate Member
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/um-user-list/admin/css/um-user-list-admin-style.css/wp-content/plugins/um-user-list/assets/css/um-user-list.css/wp-content/plugins/um-user-list/assets/js/um-user-list.js/wp-content/plugins/um-user-list/assets/js/um-user-list.jsum-user-list/assets/css/um-user-list.css?ver=um-user-list/assets/js/um-user-list.js?ver=um-user-list/admin/css/um-user-list-admin-style.css?ver=HTML / DOM Fingerprints
um-user-listum-user-list-tableum-user-list-item<!-- UM User List Widget --><!-- UM User List Shortcode --><!-- UM User List --- END OF PLUGIN CLASSES FUNCTION -->data-um-user-list-idum_user_list_ajax_object[um_user_list][um_user_list_widget]