Plugin Pulse
← Pulse

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin

by Ultimate Member · Membership

Also makes 2 other plugins · 201.8K+ installs across the portfolio →

Membership & community plugin with user profiles, registration & login, member directories, content restriction, user roles and much more.

How scoring works →
93 Health · A
Maintenance 100/100
Rating quality 85/100
Support 92/100

93 health vs 69 average across 180 Membership plugins

Directory ranking optimization

How it's scored →

How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.

96 / 100

Excellent listing optimization

Well tuned across the board

Update recency 100/100
WP compatibility 100/100
Rating quality 88/100
Listing tuning 100/100
Support resolution 88/100

Daily downloads

Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive

-67% vs prior 30d
1.1KDownloads · Aug 26

30-day downloads

Rolling 30-day volume · peaks are release surges

44.4K

now · peak 611.6K

50.5K30d downloads · Aug 26

Directory rank vs rivals

wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you

Ultimate Member · #264 you Ultimate Member · #1203 WP User Manager · #1931 Ultimate Member · #3396

Rating trend

Star average over time · dips mark rough releases

4.4Stars · Aug 26

Update activity

How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.

253per 1k installs · Aug 26

Release cadence

Actively maintained
from wp.org release tags

How often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.

8

releases in the last 12 months

2mo ago

latest release · v2.12.1

311

tagged releases on record

Recent releases

2.12.1 · 2mo ago2.12.0 · 2mo ago2.11.4 · 4mo ago2.11.3 · 5mo ago2.11.2 · 7mo ago2.11.1 · 8mo ago2.11.0 · 9mo ago2.10.6 · 11mo ago2.10.5 · 1.2y ago2.10.4 · 1.3y ago2.10.3 · 1.3y ago2.10.2 · 1.4y ago2.10.1 · 1.5y ago2.10.0 · 1.5y ago

What its installed base runs

via wordpress.org

Share of active installs on each version of this plugin. Green is the current release; a big slice on older versions is a user base that has stopped updating.

v2.12 47%
v2.11 20%
v2.10 12%
v2.8 6.4%
Older / other versions 15%

Estimated active installs

The public count shows “200K+”. Our estimate pins where the real number sits.

modeled estimate
200K–300K ≈240K

Modeled within the band wp.org reports; tightens as we track daily.

Install history · since 2015-03-10 · 1,498 observations

200KInstalls · Aug 26

Estimated value

What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.

Est. annual revenue

N/A

Est. acquisition value

N/A

No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. A declining trend compresses what a buyer would pay.

Details

Version
2.13.0
Last updated
yesterday
Added
2015-01-21 · 11 yrs old
Requires WP
6.2
Tested up to
7.1
Requires PHP
7.0

Recent reviews

All reviews on wp.org ↗
  1. laquituck
    5mo ago

    It’s very limiting; its templates are basic, you can’t control the images that users upload, and they have very low resolution, which makes it unprofessional. This topic was modified 3 months, 2 weeks ago by laquituck.

    Read on wp.org ↗
  2. Melody Chaney
    5mo ago

    This plugin never works right. It’s just one screw-up after another that I keep running into. And the support is never able to help (for free). I spend more time trying to fix this plugin than I spend working on anything else on my website. I was having a problem where my user profiles were showing the wrong profile pic. So the user profile pics were showing other people’s profile pics from other profile forms. When I asked support to help me figure out the problem, they offered to solve it for me for $100! Imagine that! They wanted to charge me $100 to fix THEIR SCREWUP! I asked them to just offer suggestions for free on how I can fix it myself. A couple of support associates refused, but I finally talked to one who did offer suggestions, although they didn’t work. I spent 3 whole days working on this until I finally figured it out myself! Now I’ve run into another problem. When I post a shortcode for a form onto a page, it pulls up the wrong form!

    Read on wp.org ↗
  3. esther0708
    7mo ago

    I have been reaching out to support and they do not reply or fix the issues. It is disappointing. I will be moving plugins This topic was modified 5 months, 3 weeks ago by esther0708.

    Read on wp.org ↗
  4. barjinder
    9mo ago

    This is a very good plugin, it helped me to implement restricted content feature on a website easily.

    Read on wp.org ↗
  5. difko
    12mo ago

    Seguramente, el mejor plugin para gestionar usuarios, permisos, bloqueos, etc.

    Read on wp.org ↗
  6. maxellinger
    1.1y ago

    I never leave reviews for plugins, but having just spent several months with Ultimate Member I feel compelled to. I was responsible for migrating a 1,000+ member organization site from an old BuddyPress setup to UM and the transition was lovely. The Stripe integration is particularly well-implemented. Some of the frontend styles and markup are a little outdated, and I would appreciate some easier styling through CSS vars, but my complaints are minimal. All the extensions and sister plugins do what they say on the tin (though the Jobs one needs maybe a little English pass).

    Read on wp.org ↗
  7. dterry
    1.2y ago

    I’m using this plugin to enhance user profile photo display and it works like a charm. Love how clean and responsive the widget is. It even respects user permissions properly exactly what I needed for a members-only area on my site. Bonus points for not breaking my layout even with heavy CSS customization.

    Read on wp.org ↗
  8. Phil
    1.4y ago

    Super plugin and easy to use.

    Read on wp.org ↗

Latest updates

via wp.org changelog

Recent releases and news for this plugin

  1. 2026-08-24 Version 2.13.0 Enhancements Added: Using illegal_user_logins filter to sanitize the user_login field value during registration or upgrade. Added: Using wp-cli/wp-config-transformer library to set Ultimate Member > API keys settings con 2.13.0
  2. 2026-07-06 Version 2.12.1 Enhancements Added: Ability to handle local website URLs resources (image, audio, video from Media Library, 3rd-party local URLs embed to iframe) in the oEmbed-type field value. Added: The API key field type for the sett 2.12.1
  3. 2026-06-12 Version 2.12.0 Bugfixes Fixed: Security issue, CVE ID: CVE-2026-7761. ** Restricted get_directory_by_hash() function to only match posts with post_type=’um_directory’ and publish post status. ** Used 0 === strpos() instead of strstr() 2.12.0

Known vulnerabilities

via Wordfence Intelligence

75 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.

  1. 2026-08-24 CVE-2026-18547 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.12.1 Patched in 2.13.0
  2. 2026-08-05 CVE-2026-12251 Incorrect Privilege Assignment Affects < 2.12.1 Patched in 2.12.1
  3. 2026-07-02 CVE-2026-8489 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.11.4 Patched in 2.12.0
  4. 2026-06-23 CVE-2026-7761 Missing Authorization Affects <= 2.11.4 Patched in 2.12.0
  5. 2026-04-03 CVE-2025-15064 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.11.1 Patched in 2.11.2
  6. 2026-03-27 CVE-2026-4248 Improper Authorization Affects <= 2.11.2 Patched in 2.11.3
  7. 2026-02-17 CVE-2026-1404 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.11.1 Patched in 2.11.2
  8. 2025-12-20 CVE-2025-13220 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.11.0 Patched in 2.11.1
  9. 2025-12-19 CVE-2025-12492 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 2.11.0 Patched in 2.11.1
  10. 2025-12-16 CVE-2025-13217 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.11.0 Patched in 2.11.1
  11. 2025-12-16 CVE-2025-14081 Incorrect Authorization Affects <= 2.11.0 Patched in 2.11.1
  12. 2025-05-07 CVE-2025-47691 Improper Control of Generation of Code ('Code Injection') Affects <= 2.10.3 Patched in 2.10.4
  13. 2025-04-16 CVE-2026-15290 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 2.10.1 Patched in 2.10.2
  14. 2025-03-04 CVE-2025-1702 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 2.10.0 Patched in 2.10.1
  15. 2025-02-20 CVE-2024-12276 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 2.9.2 Patched in 2.10.0
  16. 2025-01-17 CVE-2025-0318 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 2.9.1 Patched in 2.9.2
  17. 2025-01-17 CVE-2025-0308 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 2.9.1 Patched in 2.9.2
  18. 2024-11-20 CVE-2024-10528 Missing Authorization Affects <= 2.8.9 Patched in 2.9.0
  19. 2024-10-03 CVE-2024-8520 Cross-Site Request Forgery (CSRF) Affects <= 2.8.6 Patched in 2.8.7
  20. 2024-10-03 CVE-2024-8519 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.8.6 Patched in 2.8.7
  21. 2024-04-10 CVE-2024-2765 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.8.4 Patched in 2.8.5
  22. 2024-03-08 CVE-2024-2123 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.8.3 Patched in 2.8.4
  23. 2024-02-23 CVE-2024-1071 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects 2.1.3 - 2.8.2 Patched in 2.8.3
  24. 2023-08-08 Cross-Site Request Forgery (CSRF) Affects <= 2.6.8 Patched in 2.6.9
  25. 2023-06-29 CVE-2023-3460 Incorrect Privilege Assignment Affects <= 2.6.6 Patched in 2.6.7
  26. 2023-05-30 CVE-2023-31216 Cross-Site Request Forgery (CSRF) Affects <= 2.6.0 Patched in 2.6.1
  27. 2022-10-28 CVE-2022-2445 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects 1.0 - 2.5.0 Patched in 2.5.1
  28. 2022-10-28 CVE-2022-3361 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 2.5.0 Patched in 2.5.1
  29. 2022-10-28 CVE-2022-3384 Improper Control of Generation of Code ('Code Injection') Affects <= 2.5.0 Patched in 2.5.1
  30. 2022-10-28 CVE-2022-3383 Improper Control of Generation of Code ('Code Injection') Affects <= 2.5.0 Patched in 2.5.1
  31. 2022-07-15 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects 2.4.0 Patched in 2.4.1
  32. 2022-07-14 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 2.4.1 Patched in 2.4.2
  33. 2022-04-29 CVE-2022-1209 URL Redirection to Untrusted Site ('Open Redirect') Affects <= 2.3.1 Patched in 2.3.2
  34. 2022-03-21 CVE-2022-1208 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.3.2 Patched in 2.4.0
  35. 2021-05-07 CVE-2021-24306 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.1.20 Patched in 2.1.20
  36. 2020-12-09 CVE-2020-36170 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.1.13 Patched in 2.1.13
  37. 2020-11-09 CVE-2020-36157 Improper Privilege Management Affects < 2.1.12 Patched in 2.1.12
  38. 2020-11-09 CVE-2020-36155 Improper Privilege Management Affects < 2.1.12 Patched in 2.1.12
  39. 2020-11-09 CVE-2020-36156 Improper Privilege Management Affects < 2.1.12 Patched in 2.1.12
  40. 2020-07-23 URL Redirection to Untrusted Site ('Open Redirect') Affects < 2.1.7 Patched in 2.1.7
  41. 2020-01-13 CVE-2020-6859 Improper Privilege Management Affects < 2.1.3 Patched in 2.1.3
  42. 2019-08-12 CVE-2018-0585 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.3.88 Patched in 2.0.4
  43. 2019-08-12 CVE-2018-0587 Improper Authorization Affects <= 2.0.3 Patched in 2.0.4
  44. 2019-08-12 CVE-2018-0586 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects < 2.0.4 Patched in 2.0.4
  45. 2019-08-12 CVE-2018-20965 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.0.3 Patched in 2.0.4
  46. 2019-07-22 CVE-2019-14945 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.0.53 Patched in 2.0.54
  47. 2019-06-24 CVE-2019-14947 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.0.51 Patched in 2.0.52
  48. 2019-06-24 CVE-2019-14946 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.0.51 Patched in 2.0.52
  49. 2019-06-15 CVE-2019-10271 Missing Authorization Affects <= 2.0.39 Patched in 2.0.40
  50. 2019-06-15 CVE-2019-10270 Improper Privilege Management Affects <= 2.0.39 Patched in 2.0.40
  51. 2019-05-13 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.0.46 Patched in 2.0.46
  52. 2019-05-13 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 2.0.45 Patched in 2.0.46
  53. 2019-05-13 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.0.45 Patched in 2.0.46
  54. 2019-04-01 CVE-2019-10673 Cross-Site Request Forgery (CSRF) Affects < 2.0.40 Patched in 2.0.40
  55. 2018-11-27 Cross-Site Request Forgery (CSRF) Affects <= 2.0.32 Patched in 2.0.33
  56. 2018-10-06 CVE-2018-17866 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.0.27 Patched in 2.0.28
  57. 2018-08-09 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.0.22 Patched in 2.0.22
  58. 2018-08-08 Unrestricted Upload of File with Dangerous Type Affects < 2.0.22 Patched in 2.0.22
  59. 2018-07-03 CVE-2018-13136 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.0.17 Patched in 2.0.18
  60. 2018-05-14 CVE-2018-0589 Improper Access Control Affects <= 2.0.3 Patched in 2.0.4
  61. 2018-05-10 CVE-2018-0590 Authorization Bypass Through User-Controlled Key Affects < 2.0.4 Patched in 2.0.4
  62. 2018-05-10 CVE-2018-0588 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 2.0.39 Patched in 2.0.40
  63. 2018-05-10 CVE-2018-0587 Unrestricted Upload of File with Dangerous Type Affects < 2.0.4 Patched in 2.0.4
  64. 2018-04-23 CVE-2018-10234 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.0.11 Patched in 2.0.11
  65. 2018-04-23 CVE-2018-10233 Cross-Site Request Forgery (CSRF) Affects < 2.0.7 Patched in 2.0.7
  66. 2018-02-14 CVE-2018-6943 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.0.4 Patched in 2.0.4
  67. 2018-02-14 CVE-2018-6944 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.0 Patched in 2.0.4
  68. 2017-04-17 Missing Authorization Affects <= 1.3.83 Patched in 1.3.84
  69. 2016-12-06 Missing Authorization Affects <= 1.3.75 Patched in 1.3.76
  70. 2016-07-10 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') Affects < 1.3.65 Patched in 1.3.65
  71. 2016-04-06 CVE-2016-10872 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 1.3.40 Patched in 1.3.40
  72. 2015-12-02 CVE-2015-8354 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 1.3.29 Patched in 1.3.29
  73. 2015-08-20 CVE-2015-9304 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.3.17 Patched in 1.3.18
  74. 2015-06-18 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects 1.2.98 - 1.2.997 Patched in 1.3.0
  75. 2015-03-10 Missing Authorization Affects < 1.0.84 Patched in 1.0.84

Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.

CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.

Behavioral tests

via WP Hive

Automated install-time checks, tested on PHP 8.1.12 · WP 7.0

Low memory footprint
Low page-speed impact
Runs on latest PHP + WP
No PHP errors
No JS errors
Activates cleanly
No resource errors
No external HTTP errors
Optimized database use
Frequently updated

Languages

via translate.wordpress.org

Translated into 49 languages, 10 at 90% or more

Dutch 100%
Dutch (Formal) 100%
Lao 100%
Ukrainian 100%
Korean 99%
French (France) 97%
German 97%
German (Formal) 97%
Spanish (Chile) 94%
Spanish (Spain) 92%
Norwegian (Bokmål) 88%
Persian 77%
Russian 71%
Danish 70%
Swedish 69%
Dutch (Belgium) 68%
Arabic 66%
Chinese (China) 66%
Spanish (Ecuador) 66%
Czech 65%
Spanish (Colombia) 63%
Spanish (Venezuela) 63%
Spanish (Mexico) 61%
French (Canada) 59%

Plus 25 more locales with partial translations.

Growth timeline

Install-tier crossings we have observed, and how long each tier took to outgrow

No tier crossings observed yet.

Competes with

The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).

Compare head to head →

Embed this report card

Drop a live Pulse card for Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin into a readme, a review or a deck. It updates itself.

<iframe src="https://plugins.wpmayor.com/embed/ultimate-member" width="480" height="300" style="border:0" loading="lazy" title="Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin — Plugin Pulse"></iframe>
Preview card ↗

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: 200K+ active installs, 4.4★ (1,444 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/ultimate-member