
VI: Member Content Security & Risk Analysis
wordpress.org/plugins/vi-member-contentSite Specific Functions
Is VI: Member Content Safe to Use in 2026?
Generally Safe
Score 85/100VI: Member Content has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'vi-member-content' v9.1.200310 plugin exhibits a strong security posture based on the provided static analysis and vulnerability history. The code analysis reveals no dangerous functions, a complete absence of raw SQL queries (all use prepared statements), and 100% output escaping. Furthermore, there are no observed file operations or external HTTP requests, and the plugin properly implements capability checks. The limited attack surface, consisting only of two shortcodes with no explicitly un-protected entry points, is also a positive indicator. The lack of any recorded CVEs or past vulnerabilities further strengthens this assessment. The absence of any identified taint flows suggests that the plugin is not susceptible to common injection-style attacks.
While the plugin demonstrates excellent security practices, the absence of nonce checks on its entry points (AJAX and REST API are reported as 0, so shortcodes are the primary entry points here) represents a potential weakness. Although the current version shows no vulnerabilities, a lack of consistent nonce protection can sometimes be exploited in conjunction with other issues or in future versions if not addressed. However, given the overall clean code and the robust use of capability checks, the immediate risk is low. The plugin's strengths in input sanitization and output escaping significantly mitigate the potential impact of any theoretical attack vectors related to its shortcodes.
Key Concerns
- Shortcode entry points lack nonce checks
VI: Member Content Security Vulnerabilities
VI: Member Content Code Analysis
VI: Member Content Attack Surface
Shortcodes 2
Maintenance & Trust
VI: Member Content Maintenance & Trust
Maintenance Signals
Community Trust
VI: Member Content Alternatives
No alternatives data available yet.
VI: Member Content Developer Profile
2 plugins · 20 total installs
How We Detect VI: Member Content
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
[vi-visitor][/vi-visitor][vi-member][/vi-member]