
Wishlist Member API Testing Security & Risk Analysis
wordpress.org/plugins/wishlist-member-api-testingTest Wishlist Member API on your server
Is Wishlist Member API Testing Safe to Use in 2026?
Generally Safe
Score 100/100Wishlist Member API Testing has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wishlist-member-api-testing" plugin v1.0.4 presents a mixed security posture. On the positive side, its attack surface is remarkably small, with no detected AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, all SQL queries appear to be properly prepared, and there's no history of known vulnerabilities, which is a strong indicator of developer diligence. However, significant concerns arise from the static analysis. The presence of four dangerous function calls, specifically `unserialize`, is a major red flag. This function is notoriously insecure when used with untrusted input, as it can lead to arbitrary code execution. The taint analysis revealing two high-severity flows with unsanitized paths, combined with the `unserialize` function, strongly suggests a critical vulnerability related to deserialization. Additionally, the complete lack of output escaping for all detected outputs is another serious weakness, potentially opening the door to cross-site scripting (XSS) vulnerabilities. The absence of nonce and capability checks on any entry points, while the attack surface is zero, means that if any were to be introduced in the future without proper checks, they would be unprotected.
Key Concerns
- High severity taint flows with unsanitized paths
- Dangerous function call: unserialize
- All outputs are unescaped
- No nonce checks
- No capability checks
Wishlist Member API Testing Security Vulnerabilities
Wishlist Member API Testing Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Wishlist Member API Testing Attack Surface
WordPress Hooks 5
Maintenance & Trust
Wishlist Member API Testing Maintenance & Trust
Maintenance Signals
Community Trust
Wishlist Member API Testing Alternatives
Better WishList API
better-wlm-api
A better version of the WishList Member API. Created to make the connection to external services like ActiveCampaign and Autorespond a lot easier.
Wishlist Member AutoProtect
wishlist-auto-protect
This plugin adds option to automatically protect any post or page in WishList Member after a special period of time or on a specific date.
WishList Member: Show All Levels
wishlist-member-show-all-levels
Provides a shortcode that outputs all levels a member is allowed to access.
Member Profile Fields for WishList Member and Gravity Forms User Registration Add-On
member-profile-fields-for-wlm-and-gf-user-registration
Allows setting WishList Member Fields when users are automatically created using Gravity Forms User Registration Add-On.
Wishlist Member API Testing Developer Profile
6 plugins · 2K total installs
How We Detect Wishlist Member API Testing
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wishlist-member-api-testing/css/style.css/wp-content/plugins/wishlist-member-api-testing/js/wlmtest_toggle.js/wp-content/plugins/wishlist-member-api-testing/js/wlmtest_toggle.jswishlist-member-api-testing/css/style.css?ver=wishlist-member-api-testing/js/wlmtest_toggle.js?ver=HTML / DOM Fingerprints
wlmtest_successwlmtest_failwlmtest_toogle_triggerwlmtest_toogledata-wlmtest_level_idwlmtest_togglewlmapi_get_levels