WP eMember Integration for WooCommerce Security & Risk Analysis

wordpress.org/plugins/woocommerce-and-wp-emember-integration

An addon to integrate WooCommerce plugin with WP eMember plugin for membership payment

100 active installs v2.5 PHP + WP 3.0+ Updated Sep 21, 2025
loginmembermembersmembershipwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP eMember Integration for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

WP eMember Integration for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7mo ago
Risk Assessment

The static analysis of "woocommerce-and-wp-emember-integration" v2.5 reveals a seemingly strong security posture with zero identified entry points (AJAX, REST API, shortcodes, cron) and no dangerous functions detected. This suggests a deliberate effort to minimize the plugin's attack surface. Furthermore, the absence of any known CVEs in its vulnerability history is a positive indicator of its past security performance.

However, significant concerns arise from the code signals. The fact that 100% of SQL queries are not using prepared statements is a critical risk, exposing the plugin to potential SQL injection vulnerabilities. Similarly, the absence of any output escaping for the single identified output poses a risk of Cross-Site Scripting (XSS) attacks. The complete lack of nonce and capability checks, while potentially mitigated by the zero entry points, leaves a theoretical backdoor for unauthorized actions if any entry point were to be discovered or added in the future.

In conclusion, while the plugin demonstrates strengths in attack surface minimization and a clean vulnerability history, the severe lack of secure coding practices for SQL queries and output handling represents a substantial security weakness. The absence of checks like nonces and capabilities, though currently contained by the zero entry points, should be addressed as a proactive security measure to prevent future exploits.

Key Concerns

  • SQL queries without prepared statements
  • No output escaping detected
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

WP eMember Integration for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

WP eMember Integration for WooCommerce Release Timeline

v2.5Current
v2.4
v2.3
v2.2
v1.4
Code Analysis
Analyzed Mar 16, 2026

WP eMember Integration for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

0% escaped1 total outputs
Attack Surface

WP eMember Integration for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionset_logged_in_cookieemember-woocommerce-addon.php:20
actionadd_meta_boxesemember-woocommerce-addon.php:40
actionsave_postemember-woocommerce-addon.php:54
actionwoocommerce_order_status_processingemember-woocommerce-addon.php:67
actionwoocommerce_order_status_completedemember-woocommerce-addon.php:68
actionwoocommerce_checkout_order_processedemember-woocommerce-addon.php:69
actionsubscriptions_cancelled_for_orderemember-woocommerce-addon.php:231
actionsubscriptions_expired_for_orderemember-woocommerce-addon.php:232
Maintenance & Trust

WP eMember Integration for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 21, 2025
PHP min version
Downloads16K

Community Trust

Rating60/100
Number of ratings4
Active installs100
Developer Profile

WP eMember Integration for WooCommerce Developer Profile

mra13

15 plugins · 210K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
616 days
View full developer profile
Detection Fingerprints

How We Detect WP eMember Integration for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

HTML Comments
<!-- WP eMember Membership -->
Data Attributes
name="emember_woo_product_level_id"id="emember-woo-product-data"
FAQ

Frequently Asked Questions about WP eMember Integration for WooCommerce