
WP Security Audit Log addon for Paid Memberships Pro Security & Risk Analysis
wordpress.org/plugins/wp-security-audit-log-for-paid-memberships-proAn Addon to the WP Security Audit Log plugin to log events from Paid Memberships Pro plugin
Is WP Security Audit Log addon for Paid Memberships Pro Safe to Use in 2026?
Generally Safe
Score 85/100WP Security Audit Log addon for Paid Memberships Pro has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'wp-security-audit-log-for-paid-memberships-pro' v1.1.5 exhibits a generally strong security posture based on the provided static analysis. The absence of identified AJAX handlers, REST API routes, shortcodes, cron events, and file operations significantly limits the potential attack surface. Furthermore, the code analysis shows no dangerous functions, file operations, external HTTP requests, or taint flows, which are all positive indicators. The presence of capability checks and the proper escaping of all identified outputs are commendable security practices.
However, a significant concern arises from the handling of SQL queries. With 10 total SQL queries and 0% utilizing prepared statements, this presents a substantial risk of SQL injection vulnerabilities. While no vulnerabilities are currently recorded in the history and no critical taint flows were detected, the raw SQL usage creates an inherent weakness that could be exploited if an attacker can influence the data used in these queries. The lack of nonce checks on potential entry points, though the entry points are currently zero, is a potential oversight if new entry points are added without proper security considerations.
In conclusion, the plugin demonstrates good practices in limiting its attack surface and handling output. The primary weakness lies in its insecure handling of SQL queries, which requires immediate attention. The absence of historical vulnerabilities is positive but does not negate the risk posed by the current code's SQL practices. Addressing the raw SQL queries should be the top priority to bolster the plugin's overall security.
Key Concerns
- Raw SQL queries without prepared statements
WP Security Audit Log addon for Paid Memberships Pro Security Vulnerabilities
WP Security Audit Log addon for Paid Memberships Pro Release Timeline
WP Security Audit Log addon for Paid Memberships Pro Code Analysis
SQL Query Safety
Output Escaping
WP Security Audit Log addon for Paid Memberships Pro Attack Surface
WordPress Hooks 23
Maintenance & Trust
WP Security Audit Log addon for Paid Memberships Pro Maintenance & Trust
Maintenance Signals
Community Trust
WP Security Audit Log addon for Paid Memberships Pro Alternatives
Administrator Access to PMPro Protected Content
administrator-access-to-pmpro-protected-content
Overrides the PMPro "Require Membership" settings and grants view access to any user assigned to the WordPress "Administrator" rol …
E20R Better Members List for Paid Memberships Pro
e20r-members-list
Extensible, sortable & bulk action capable members listing + export to CSV tool for Paid Memberships Pro.
Aspexi Login Audit
aspexi-login-audit
This plugin helps you to keep an audit trail of user login activities such as successful login, logout, failed login and more to ensure your site perf …
First Data for Paid Memberships Pro
first-data-for-pmpro
First Data for Paid Memberships Pro allows merchants to accept all major credit cards for both one-time and recurring membership payments.
Zesty Custom Post Types for Paid Memberships Pro
zesty-custom-post-types-for-paid-memberships-pro
Restrict any custom post type with Paid Memberships Pro.
WP Security Audit Log addon for Paid Memberships Pro Developer Profile
1 plugin · 10 total installs
How We Detect WP Security Audit Log addon for Paid Memberships Pro
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-security-audit-log-for-paid-memberships-pro/pmpro-alerts.phpwp-security-audit-log-for-paid-memberships-pro/wp-security-audit-log-for-paid-memberships-pro.php?ver=