
Wishlist Member AutoProtect Security & Risk Analysis
wordpress.org/plugins/wishlist-auto-protectThis plugin adds option to automatically protect any post or page in WishList Member after a special period of time or on a specific date.
Is Wishlist Member AutoProtect Safe to Use in 2026?
Generally Safe
Score 85/100Wishlist Member AutoProtect has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wishlist-auto-protect" plugin v1.1.0 exhibits a mixed security posture. While it has a small attack surface and appears to implement some security measures like capability checks and a nonce check, significant concerns arise from the static analysis. The presence of the dangerous `exec` function, combined with two critical severity taint flows involving unsanitized paths, indicates a high potential for remote code execution vulnerabilities. Furthermore, the fact that 100% of its outputs are not properly escaped presents a risk of cross-site scripting (XSS) attacks. Although the plugin has no recorded vulnerability history, this should not be interpreted as a sign of robust security, especially given the critical findings in the static analysis. The lack of historical vulnerabilities might simply mean it hasn't been thoroughly scrutinized or exploited yet. The plugin's strengths lie in its limited entry points and the inclusion of some protective measures, but these are overshadowed by the critical code signals and taint analysis results.
Key Concerns
- Critical taint flow found
- Critical taint flow found
- Dangerous function detected (exec)
- Output escaping is missing
- SQL query not using prepared statements
- Flow with unsanitized paths
Wishlist Member AutoProtect Security Vulnerabilities
Wishlist Member AutoProtect Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Wishlist Member AutoProtect Attack Surface
Shortcodes 1
WordPress Hooks 11
Scheduled Events 1
Maintenance & Trust
Wishlist Member AutoProtect Maintenance & Trust
Maintenance Signals
Community Trust
Wishlist Member AutoProtect Alternatives
Wishlist Member API Testing
wishlist-member-api-testing
Test Wishlist Member API on your server
WishList Member: Show All Levels
wishlist-member-show-all-levels
Provides a shortcode that outputs all levels a member is allowed to access.
Members – Membership & User Role Editor Plugin
members
The best WordPress membership and user role editor plugin. User Roles & Capabilities editor helps you restrict content in just a few clicks.
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
ultimate-member
Membership & community plugin with user profiles, registration & login, member directories, content restriction, user roles and much more.
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
wp-user-avatar
Setup paid membership, accept payment, sell subscription & digital product, paywall, create login & registration form, user profile & member directory
Wishlist Member AutoProtect Developer Profile
6 plugins · 2K total installs
How We Detect Wishlist Member AutoProtect
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
id="atc-enable-status"name="atc-enable-status"id="atc-expire-days"name="atc-expire-days"id="atc-expire-option"name="atc-expire-option"+3 more