
WM Workout Manager Security & Risk Analysis
wordpress.org/plugins/wm-workout-managerA lightweight plugin to manage and display workout plans and exercises with shortcodes and customizable templates.
Is WM Workout Manager Safe to Use in 2026?
Generally Safe
Score 100/100WM Workout Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wm-workout-manager" plugin v1.1.0 exhibits a generally good security posture with several strong security practices in place. The absence of known CVEs and the thorough use of prepared statements for all SQL queries are significant strengths. Furthermore, the plugin demonstrates excellent output escaping with 96% of outputs properly handled, and it includes nonce checks and capability checks, indicating an awareness of common WordPress security vulnerabilities. The bundled library, Select2, is noted, but its version is not specified for further analysis regarding potential vulnerabilities within it.
However, a notable concern arises from the presence of one unprotected AJAX handler within the plugin's attack surface. This unprotected entry point could potentially be exploited by unauthenticated users if it handles user-supplied input without proper validation or sanitization, even though no critical taint flows were identified in the static analysis. The limited scope of the taint analysis (0 flows analyzed) means that this area might not have been fully explored, leaving a potential gap.
Overall, the plugin is built on a solid foundation with many security best practices. The primary area for improvement is securing the identified unprotected AJAX endpoint. The lack of historical vulnerabilities is a positive indicator of the developers' diligence, but ongoing vigilance, especially concerning the unprotected entry point, is crucial.
Key Concerns
- Unprotected AJAX handler found
WM Workout Manager Security Vulnerabilities
WM Workout Manager Code Analysis
Bundled Libraries
Output Escaping
WM Workout Manager Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 18
Maintenance & Trust
WM Workout Manager Maintenance & Trust
Maintenance Signals
Community Trust
WM Workout Manager Alternatives
AldoOne-Workout
aldoone-workout
A responsive and simple way to display your workouts. Create new workouts, add exercises, descriptions, video links and copy-paste the shortcode into …
Gym Builder – Fitness, Gym, Class Schedule Maker Plugin
gym-builder
GymBuilder simplifies gym management with class schedules,trainer profiles,fitness calculators,member management,and shortcode generators.
Dailymile Widgets
dailymile-widgets
Share your latest workout with Dailymile widgets in your WordPress sidebar. Widgets are cached so your pages load faster.
Flogger
flogger
Tag your posts with the exercises you did that day, including how much (e.g. steps, minutes, reps, etc.)
Go Exercise
go-exercise
A plugin Designed specifically for the small gym owner. Create exercises for your members and display exactly which areas of the body they are working …
WM Workout Manager Developer Profile
1 plugin · 20 total installs
How We Detect WM Workout Manager
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wm-workout-manager/admin/css/woma-workout-manager-admin.css/wp-content/plugins/wm-workout-manager/admin/js/woma-workout-manager-admin.js/wp-content/plugins/wm-workout-manager/admin/css/select2.min.css/wp-content/plugins/wm-workout-manager/admin/js/select2.min.js/wp-content/plugins/wm-workout-manager/admin/js/woma-workout-plan-admin.js/wp-content/plugins/wm-workout-manager/admin/js/woma-workout-edit-workouts.js/wp-content/plugins/wm-workout-manager/admin/css/woma-workout-manager-workouts.css/wp-content/plugins/wm-workout-manager/admin/js/woma-options.jswm-workout-manager/admin/css/woma-workout-manager-admin.css?ver=wm-workout-manager/admin/js/woma-workout-manager-admin.js?ver=wm-workout-manager/admin/css/select2.min.css?ver=wm-workout-manager/admin/js/select2.min.js?ver=wm-workout-manager/admin/js/woma-workout-plan-admin.js?ver=wm-workout-manager/admin/js/woma-workout-edit-workouts.js?ver=wm-workout-manager/admin/css/woma-workout-manager-workouts.css?ver=wm-workout-manager/admin/js/woma-options.js?ver=HTML / DOM Fingerprints
woma-workout-containerwoma-workout-headerwoma-workout-contentwoma-workout-metawoma-exercise-itemwoma-exercise-drag-handlewoma-exercise-detailswoma-exercise-name+9 moredata-workout-iddata-exercise-iddata-post-type="workout"womaWorkoutMetawomaAdmin[wm_workout_display][wm_workout_plan]