
Unilevel MLM Plan Security & Risk Analysis
wordpress.org/plugins/unilevel-mlm-planUnilevel MLM Plan software has been design to help customers to make the high profit gain based on level.
Is Unilevel MLM Plan Safe to Use in 2026?
Generally Safe
Score 99/100Unilevel MLM Plan has a strong security track record. Known vulnerabilities have been patched promptly.
The 'unilevel-mlm-plan' v2.1 plugin presents a mixed security posture. While it demonstrates good practices in using prepared statements for SQL queries and a reasonable rate of output escaping, significant concerns arise from its attack surface. All 14 identified AJAX handlers lack authentication checks, creating a large entry point for potential unauthorized actions. Furthermore, the taint analysis reveals 5 flows with unsanitized paths, and all of these are classified as high severity, indicating a tangible risk of vulnerabilities like Cross-Site Scripting (XSS) or other forms of injection if user-supplied data is not properly handled before being processed or displayed. The plugin's vulnerability history, featuring a medium-severity CVE related to XSS, reinforces these concerns, suggesting a pattern where input sanitization has been a past weakness. Although the current CVE is patched, the presence of high-severity taint flows without corresponding capability checks on AJAX handlers is a critical area of immediate concern. The lack of capability checks on the AJAX handlers is a significant oversight.
Key Concerns
- 14 unprotected AJAX handlers
- 5 high severity unsanitized taint flows
- No capability checks on AJAX handlers
- Medium severity CVE history (XSS)
- 79% output escaping (not 100%)
Unilevel MLM Plan Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Unilevel MLM Plan <= 1.1.0 - Reflected Cross-Site Scripting via 'page'
Unilevel MLM Plan Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Unilevel MLM Plan Attack Surface
AJAX Handlers 14
WordPress Hooks 13
Maintenance & Trust
Unilevel MLM Plan Maintenance & Trust
Maintenance Signals
Community Trust
Unilevel MLM Plan Alternatives
Binary MLM For WooCommerce
woo-binary-mlm
Binary MLM plugin for WooCommerce with advanced features to manage users, commissions, and eCommerce growth.
MLM Soft Integration
mlm-soft-integration
Plugin integrates your Wordpress site with your instance of mlm-soft.com cloud platform.
BuddyPress
buddypress
Get together safely, in your own way, in WordPress.
Simple Social Icons
simple-social-icons
This plugin provides two ways to display social icons: a traditional widget (available on all WordPress versions) and block variations for the core So …
Lightweight Social Icons
lightweight-social-icons
Looking to add simple social icons to your widget areas? Choose the size and color of your icons, and then choose from 47 different social profiles.
Unilevel MLM Plan Developer Profile
5 plugins · 80 total installs
How We Detect Unilevel MLM Plan
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/unilevel-mlm-plan/assets/css/bootstrap.css/wp-content/plugins/unilevel-mlm-plan/assets/css/ump.css/wp-content/plugins/unilevel-mlm-plan/assets/js/main.js/wp-content/plugins/unilevel-mlm-plan/assets/js/chart.js/wp-content/plugins/unilevel-mlm-plan/assets/js/bootstrap.min.js/wp-content/plugins/unilevel-mlm-plan/assets/js/bootstrap.bundle.min.js/wp-content/plugins/unilevel-mlm-plan/assets/css/admin.css/wp-content/plugins/unilevel-mlm-plan/assets/js/admin.js/wp-content/plugins/unilevel-mlm-plan/assets/js/main.js/wp-content/plugins/unilevel-mlm-plan/assets/js/chart.js/wp-content/plugins/unilevel-mlm-plan/assets/js/bootstrap.min.js/wp-content/plugins/unilevel-mlm-plan/assets/js/bootstrap.bundle.min.js/wp-content/plugins/unilevel-mlm-plan/assets/js/admin.jsunilevel-mlm-plan/assets/css/bootstrap.css?ver=unilevel-mlm-plan/assets/css/ump.css?ver=unilevel-mlm-plan/assets/js/main.js?ver=unilevel-mlm-plan/assets/js/chart.js?ver=1.0.0unilevel-mlm-plan/assets/js/bootstrap.min.js?ver=unilevel-mlm-plan/assets/js/bootstrap.bundle.min.js?ver=unilevel-mlm-plan/assets/css/admin.css?ver=unilevel-mlm-plan/assets/js/admin.js?ver=HTML / DOM Fingerprints
ump-register-formump-downlines-wrapperdata-ump-user-idump_ajax_obj/wp-json/ump/v1/register/wp-json/ump/v1/check-username/wp-json/ump/v1/check-email/wp-json/ump/v1/check-epin[ump_register_form][ump_downlines]