Plugin Pulse
← Pulse

ProfileGrid – User Profiles, Groups and Communities

by Metagauss · Membership

Also makes 6 other plugins · 86.3K+ installs across the portfolio →

Custom user profiles plugin ❤ with paid memberships, groups, communities, content restriction, user registration, messaging, WooCommerce memberships, …

How scoring works →
89 Health · A
Maintenance 100/100
Rating quality 91/100
Support 70/100

89 health vs 69 average across 179 Membership plugins

Directory ranking optimization

How it's scored →

How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.

88 / 100

Excellent listing optimization

Biggest win: Support resolution

Update recency 100/100
WP compatibility 100/100
Rating quality 90/100
Listing tuning 100/100
Support resolution 33/100

To rank higher: Mark more forum threads resolved — the resolved ratio feeds the ranking.

Get the full rank-higher report →

Daily downloads

Since 2022-10-05 · 1,425 days · wp.org + Plugin Pulse archive

-84% vs prior 30d
56Downloads · Aug 26

30-day downloads

Rolling 30-day volume · peaks are release surges

2.9K

now · peak 22.7K

2.8K30d downloads · Aug 26

Directory rank vs rivals

wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you

ProfileGrid · #3101 you Ultimate Member · #264 Ultimate Member · #1204 WP User Manager · #1937

Rating trend

Star average over time · dips mark rough releases

4.6Stars · Aug 26

Update activity

How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.

565per 1k installs · Aug 26

Release cadence

Actively maintained
from wp.org release tags

How often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.

31

releases in the last 12 months

2mo ago

latest release · v5.9.9.9

389

tagged releases on record

Recent releases

5.9.9.9 · 2mo ago5.9.9.8 · 2mo ago5.9.9.7 · 2mo ago5.9.9.6 · 2mo ago5.9.9.5 · 3mo ago5.9.9.4 · 3mo ago5.9.9.3 · 3mo ago5.9.9.2 · 4mo ago5.9.9.1 · 4mo ago5.9.9.0 · 5mo ago5.9.8.6 · 5mo ago5.9.8.5 · 5mo ago5.9.8.4 · 6mo ago5.9.8.3 · 6mo ago

What its installed base runs

via wordpress.org

Share of active installs on each version of this plugin. Green is the current release; a big slice on older versions is a user base that has stopped updating.

v5.9 93%
Older / other versions 6.8%

Estimated active installs

The public count shows “5K+”. Our estimate pins where the real number sits.

tracked estimate
5K–6K ≈5.6K

Refined from the date this plugin crossed into its current band.

Install history · since 2016-12-26 · 1,432 observations

5KInstalls · Aug 26

Estimated value

What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.

Est. annual revenue

N/A

Est. acquisition value

N/A

No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. A small install base leaves thin data to model from. A declining trend compresses what a buyer would pay.

Details

Version
6.0.0.1
Last updated
28d ago
Added
2016-11-30 · 9 yrs old
Requires WP
3.5
Tested up to
7.0.4
Requires PHP
7.4

Recent reviews

All reviews on wp.org ↗
  1. Roland
    3mo ago

    As our platform architecture slowly approaches a stable and coherent form, I find myself increasingly grateful for the flexibility and possibilities this plugin has offered me along the way. What began as a technical integration gradually became an important part of shaping the human structure of the planed community space. The staff, the support team has always been present with patience, professionalism, and care. Many questions, experiments, adjustments, and difficult implementation moments became manageable through their responsiveness and openness. Building a platform centered around human presence and meaningful interaction requires tools that allow freedom, adaptability, and continuity. ProfileGrid gave me exactly that. My sincere gratitude to the entire team for the work, thought, and support behind this project.

    Read on wp.org ↗
  2. vlrrml
    5mo ago

    A modern plugin effectively managing user profile and social communities. Still exploring all its rich features but it looks really great! I’m really fond of it. It has great potentials and for a small educational project like mine it is affordable. The technical support is friendly and prompt in replying to questions, which makes easy for users to find the way to the multiple features available with ProfileGrid: excellent, well done! This topic was modified 2 months, 3 weeks ago by vlrrml. This topic was modified 2 months, 3 weeks ago by vlrrml.

    Read on wp.org ↗
  3. tdcktz
    8mo ago

    This plugin is feature-rich; I really like it and am very grateful. However, when I visit “My Profile” (/myprofile/?uid=1), my page can load and be accessed, but I can’t scroll or properly display the content below. I’m not sure what the reason is—could you help me take a look? Thanks again. Additional information: 1. The theme I’m currently using is Heropress developed by Speciatheme. 2. Accessing on mobile devices works fine. 3. WordPress, the theme, and the plugin are all updated to the latest versions.

    Read on wp.org ↗
  4. Ignazio Mazzoli
    9mo ago

    Profile grid è un ottimo programma per avere l’anagrafe degli autori e sostenitori del giornale UNOeTRE.it. E’ funzionale e si aggiorna con facilità. Raccoglie tutti i dati indispensabili con foto e biografie. This topic was modified 7 months, 1 week ago by Ignazio Mazzoli.

    Read on wp.org ↗
  5. kazuki1981
    10mo ago

    They responded very quickly and provided excellent support. Thanks!

    Read on wp.org ↗
  6. Guido Cappellini
    11mo ago

    Just a few minor issues with data display, which were resolved the following day.I think it’s a really good solution for managing user groups; simple, yet comprehensive and effective.

    Read on wp.org ↗
  7. Michael
    1.0y ago

    They provided support promptly, and their suggestion was effective the first time.

    Read on wp.org ↗
  8. steveck722
    1.1y ago

    I chose ProfileGrid for my site because of all it offers, at a reasonable price. Thank you for the great work on PG!

    Read on wp.org ↗

Latest updates

via wp.org changelog

Recent releases and news for this plugin

  1. Version 6.0.0.0 Fixed: Hardened ProfileGrid REST API authorization for high-risk user, group, and membership actions. Fixed: Prevented unauthorized REST access to user, group member, and membership request data. Fixed: Secured group mem 6.0.0.0
  2. Version 5.9.9.9 Added: Security improvements. 5.9.9.9
  3. Version 5.9.9.8 Added: Security improvements. 5.9.9.8
  4. Version 5.9.9.7 Added: Security improvements 5.9.9.7
  5. Version 5.9.9.6 Added: Security improvements Added: Minor UI changes 5.9.9.6
  6. Version 5.9.9.5 Minor UI fixes. Multiple bug fixes and improvements. 5.9.9.5

Known vulnerabilities

via Wordfence Intelligence

63 disclosed vulnerabilities on record for this plugin, 1 still affects the current version.

  1. 2026-08-02 CVE-2026-16291 Authorization Bypass Through User-Controlled Key Affects < 5.9.9.8 Patched in 5.9.9.8
  2. 2026-07-30 CVE-2026-16290 Missing Authorization Affects <= 5.0.0.0 Patched in 6.0.0.0
  3. 2026-07-24 CVE-2026-16289 Missing Authorization Affects <= 5.0.0.0 Patched in 6.0.0.0
  4. 2026-07-10 CVE-2026-12687 Improper Input Validation Affects < 5.9.9.8 Patched in 5.9.9.8
  5. 2026-07-08 CVE-2026-57697 Weak Password Requirements Affects <= 5.9.9.6 Patched in 5.9.9.7
  6. 2026-07-03 CVE-2026-12689 Missing Authorization Affects <= 5.9.9.6 Patched in 5.9.9.7
  7. 2026-07-03 CVE-2026-12690 Missing Authorization Affects <= 5.9.9.6 Patched in 5.9.9.7
  8. 2026-07-03 CVE-2026-12688 Improper Access Control Affects <= 5.9.9.6 Patched in 5.9.9.7
  9. 2026-07-02 CVE-2026-57759 Cross-Site Request Forgery (CSRF) Affects <= 5.9.9.8 No patch available
  10. 2026-06-29 CVE-2026-12073 Authorization Bypass Through User-Controlled Key Affects <= 5.9.9.5 Patched in 5.9.9.6
  11. 2026-06-22 CVE-2026-4610 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 5.9.9.2 Patched in 5.9.9.3
  12. 2026-05-12 CVE-2026-4608 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 5.9.8.4 Patched in 5.9.8.5
  13. 2026-05-12 CVE-2026-4607 Missing Authorization Affects <= 5.9.8.4 Patched in 5.9.8.5
  14. 2026-05-12 CVE-2026-4609 Missing Authorization Affects <= 5.9.8.4 Patched in 5.9.8.5
  15. 2026-03-23 CVE-2026-25417 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 5.9.8.1 Patched in 5.9.8.2
  16. 2026-03-06 CVE-2026-2488 Missing Authorization Affects <= 5.9.8.1 Patched in 5.9.8.2
  17. 2026-03-06 CVE-2026-2494 Cross-Site Request Forgery (CSRF) Affects <= 5.9.8.2 Patched in 5.9.8.3
  18. 2026-02-04 CVE-2026-1271 Authorization Bypass Through User-Controlled Key Affects <= 5.9.7.2 Patched in 5.9.7.3
  19. 2026-02-04 CVE-2025-13416 Missing Authorization Affects <= 5.9.7.2 Patched in 5.9.7.3
  20. 2025-09-01 CVE-2025-4957 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 5.9.5.7 Patched in 5.9.5.8
  21. 2025-07-24 CVE-2025-49033 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 5.9.5.3 Patched in 5.9.5.4
  22. 2025-07-15 CVE-2025-6977 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 5.9.5.4 Patched in 5.9.5.5
  23. 2025-07-10 CVE-2025-49876 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 5.9.5.2 Patched in 5.9.5.3
  24. 2025-06-19 CVE-2025-52719 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 5.9.5.2 Patched in 5.9.5.3
  25. 2025-06-12 CVE-2025-49877 Server-Side Request Forgery (SSRF) Affects <= 5.9.5.2 Patched in 5.9.5.3
  26. 2025-05-16 CVE-2025-48079 Missing Authorization Affects <= 5.9.5.1 Patched in 5.9.5.2
  27. 2025-05-12 CVE-2025-47478 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 5.9.5.0 Patched in 5.9.5.1
  28. 2025-04-17 CVE-2025-39586 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 5.9.4.8 Patched in 5.9.4.9
  29. 2025-03-21 CVE-2025-0724 Deserialization of Untrusted Data Affects <= 5.9.4.5 Patched in 5.9.4.6
  30. 2025-03-21 CVE-2025-1408 Missing Authorization Affects <= 5.9.4.4 Patched in 5.9.4.5
  31. 2025-03-21 CVE-2025-0723 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 5.9.4.7 Patched in 5.9.4.8
  32. 2025-02-23 CVE-2025-26999 Deserialization of Untrusted Data Affects <= 5.9.4.3 Patched in 5.9.4.4
  33. 2025-02-17 CVE-2024-13740 Authorization Bypass Through User-Controlled Key Affects <= 5.9.4.2 Patched in 5.9.4.3
  34. 2025-02-17 CVE-2024-13741 Server-Side Request Forgery (SSRF) Affects <= 5.9.4.2 Patched in 5.9.4.3
  35. 2024-11-19 CVE-2024-10900 Missing Authorization Affects <= 5.9.3.6 Patched in 5.9.3.7
  36. 2024-10-14 CVE-2024-49273 Cross-Site Request Forgery (CSRF) Affects <= 5.9.3 Patched in 5.9.3.1
  37. 2024-09-25 CVE-2024-8861 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 5.9.3.2 Patched in 5.9.3.3
  38. 2024-07-09 CVE-2024-6410 Authorization Bypass Through User-Controlled Key Affects <= 5.8.9 Patched in 5.9.0
  39. 2024-07-09 CVE-2024-6411 Improper Privilege Management Affects <= 5.8.9 Patched in 5.9.0
  40. 2024-07-01 CVE-2024-37453 Missing Authorization Affects <= 5.8.7 Patched in 5.8.8
  41. 2024-06-04 CVE-2024-5453 Missing Authorization Affects <= 5.8.6 Patched in 5.8.7
  42. 2024-04-26 CVE-2024-30241 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 5.7.1 Patched in 5.7.2
  43. 2024-04-22 CVE-2024-32808 Authorization Bypass Through User-Controlled Key Affects <= 5.7.9 Patched in 5.8.0
  44. 2024-04-22 CVE-2024-32774 Improper Authorization Affects <= 5.8.2 Patched in 5.8.3
  45. 2024-04-22 CVE-2024-32772 Authorization Bypass Through User-Controlled Key Affects <= 5.7.9 Patched in 5.8.0
  46. 2024-04-16 CVE-2024-3606 Missing Authorization Affects <= 5.8.3 Patched in 5.8.4
  47. 2024-04-08 CVE-2024-31362 Cross-Site Request Forgery (CSRF) Affects <= 5.7.8 Patched in 5.7.9
  48. 2024-04-05 CVE-2024-31291 Authorization Bypass Through User-Controlled Key Affects <= 5.7.6 Patched in 5.7.7
  49. 2024-03-28 CVE-2024-30490 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 5.7.8 Patched in 5.7.9
  50. 2024-03-28 CVE-2024-30491 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 5.7.8 Patched in 5.7.9
  51. 2024-03-28 CVE-2024-30513 Authorization Bypass Through User-Controlled Key Affects <= 5.7.2 Patched in 5.7.3
  52. 2023-12-28 CVE-2023-52117 Missing Authorization Affects <= 5.6.6 Patched in 5.6.7
  53. 2023-11-07 CVE-2023-47644 Cross-Site Request Forgery (CSRF) Affects <= 5.7.1 Patched in 5.7.2
  54. 2023-07-17 CVE-2023-3713 Missing Authorization Affects <= 5.5.1 Patched in 5.5.2
  55. 2023-07-17 CVE-2023-3404 Use of Hard-coded Cryptographic Key Affects <= 5.5.0 Patched in 5.5.1
  56. 2023-07-17 CVE-2023-3714 Missing Authorization Affects <= 5.5.2 Patched in 5.5.3
  57. 2023-07-17 CVE-2023-3403 Missing Authorization Affects <= 5.5.1 Patched in 5.5.2
  58. 2023-02-27 CVE-2023-0940 Missing Authorization Affects <= 5.3.0 Patched in 5.3.1
  59. 2022-11-17 CVE-2022-41791 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Affects <= 5.1.7 Patched in 5.1.8
  60. 2022-10-27 CVE-2022-36352 Missing Authorization Affects <= 5.0.3 Patched in 5.0.4
  61. 2022-10-19 CVE-2022-3578 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 5.1.0 Patched in 5.1.1
  62. 2022-01-18 CVE-2022-0233 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.7.4 Patched in 4.7.7
  63. 2018-05-18 CVE-2019-15873 Improper Control of Generation of Code ('Code Injection') Affects < 2.8.6 Patched in 2.8.6

Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.

CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.

Behavioral tests

via WP Hive

Automated install-time checks, tested on PHP 8.1.12 · WP 7.0

Low memory footprint
Low page-speed impact
Runs on latest PHP + WP
No PHP errors
No JS errors
Activates cleanly
No resource errors
No external HTTP errors
Optimized database use
Frequently updated

Languages

via translate.wordpress.org

Translated into 28 languages, 6 at 90% or more

Lao 98%
Dutch 94%
French (Canada) 92%
Indonesian 92%
Turkish 92%
Czech 91%
Danish 86%
Chinese (China) 85%
Romanian 84%
German 82%
Spanish (Colombia) 81%
Russian 80%
Spanish (Chile) 80%
Spanish (Spain) 80%
Slovak 76%
Dutch (Belgium) 73%
Spanish (Argentina) 70%
Swedish 69%
Portuguese (Brazil) 66%
Polish 65%
Spanish (Venezuela) 65%
Italian 63%
French (France) 55%
Ukrainian 45%

Plus 4 more locales with partial translations.

Growth timeline

Install-tier crossings we have observed, and how long each tier took to outgrow

  1. 2026-07-10 6K+ → 5K+ down after 283 days in tier
  2. 2025-09-30 7K+ → 6K+ down after 994 days in tier
  3. 2023-01-10 8K+ → 7K+ down

Competes with

The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).

Compare head to head →

Embed this report card

Drop a live Pulse card for ProfileGrid – User Profiles, Groups and Communities into a readme, a review or a deck. It updates itself.

<iframe src="https://plugins.wpmayor.com/embed/profilegrid-user-profiles-groups-and-communities" width="480" height="300" style="border:0" loading="lazy" title="ProfileGrid – User Profiles, Groups and Communities — Plugin Pulse"></iframe>
Preview card ↗

ProfileGrid – User Profiles, Groups and Communities: 5K+ active installs, 4.6★ (236 reviews). Plugin Pulse (WP Mayor), as of 2026-08-29. https://plugins.wpmayor.com/plugin/profilegrid-user-profiles-groups-and-communities