Plugin Pulse
← Pulse

User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder

by wpeverest · Membership

Also makes 5 other plugins · 140.8K+ installs across the portfolio →

Build membership sites with tiered plans, content restriction, drag-&-drop custom registration & login form builder, and built-in payment system.

How scoring works →
98 Health · A
Maintenance 100/100
Rating quality 95/100
Support 100/100

98 health vs 69 average across 180 Membership plugins

Directory ranking optimization

How it's scored →

How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.

99 / 100

Excellent listing optimization

Well tuned across the board

Update recency 100/100
WP compatibility 100/100
Rating quality 95/100
Listing tuning 100/100
Support resolution 100/100

Daily downloads

Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive

-27% vs prior 30d
871Downloads · Aug 26

30-day downloads

Rolling 30-day volume · peaks are release surges

48.1K

now · peak 151.4K

47.8K30d downloads · Aug 26

Directory rank vs rivals

wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you

User Registration & · #713 you Ultimate Member · #264 Paid Membership Plug · #348 User Frontend · #1330

Rating trend

Star average over time · dips mark rough releases

4.8Stars · Aug 26

Update activity

How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.

957per 1k installs · Aug 26

Release cadence

Actively maintained
from wp.org release tags

How often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.

28

releases in the last 12 months

2mo ago

latest release · v5.2.5

189

tagged releases on record

Recent releases

5.2.5 · 2mo ago5.2.4 · 2mo ago5.2.3 · 2mo ago5.2.2 · 2mo ago5.2.1 · 3mo ago5.2.0 · 3mo ago5.1.6 · 4mo ago5.1.5 · 5mo ago5.1.4 · 6mo ago5.1.3 · 6mo ago5.1.2 · 6mo ago5.1.1 · 7mo ago5.1.0 · 7mo ago5.0.4 · 7mo ago

What its installed base runs

via wordpress.org

Share of active installs on each version of this plugin · 47% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.

v5.2 47%
v5.1 12%
v4.4 8.6%
Older / other versions 32%

Estimated active installs

The public count shows “50K+”. Our estimate pins where the real number sits.

tracked estimate
50K–60K ≈57K

Refined from the date this plugin crossed into its current band.

Install history · since 2018-03-16 · 1,447 observations

50KInstalls · Aug 26

Estimated value

What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.

Est. annual revenue

N/A

Est. acquisition value

N/A

No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. A declining trend compresses what a buyer would pay.

Details

Version
5.2.7
Last updated
13d ago
Added
2017-07-06 · 9 yrs old
Requires WP
5.5
Tested up to
7.0.4
Requires PHP
7.4

Latest updates

via wp.org changelog

Recent releases and news for this plugin

  1. Version 5.2.6 Enhance – Compatibility with divi 5. Enhance – Allow 100% discount coupons on memberships. Enhance – Redirect hint links to Enable Custom Redirect setting. Fix – Local currency bugs. Fix – Double Charge on Upgrade. Fix – 5.2.6
  2. Version 5.2.5 Enhance – Defer expiry to period end. Enhance – Pin Stripe subscription payment method for reliable renewals. Fix – User and admin email order. Fix – Payment fail case for paypal. Fix – Lost Password Carrot adjustment. F 5.2.5
  3. Version 5.2.4 Enhance – User role overwritten on new membership assignment. Enhance – Add customizable membership registration success message in settings. Fix – Duplicate variable. Fix – Invoice dynamic content not translatable. Fix 5.2.4
  4. Version 5.2.3 Fix – validation for receiver email and payment amount in PayPal IPN handling. Fix – Selected membership tier during registration missed proper validation, allowing assignment of off-form membership tiers. Fix – Stripe s 5.2.3
  5. Version 5.2.2 Dev – Add UR_WPML compatibility service class. Fix – Password reset link shows “invalid or expired” error. Fix – Membership subscriptions stuck pending on 3D Secure (SCA) cards. Fix – Hardcoded database table names causi 5.2.2
  6. Version 5.2.1 Fix – Stripe order validation issue. Fix – Membership upgrade action not available after disabling group add-on. Fix – Custom emails addon cannot be enabled with plus plan even available in personal. Fix – Nav menu items 5.2.1

Known vulnerabilities

via Wordfence Intelligence

48 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.

  1. 2026-08-14 CVE-2026-73995 Missing Authorization Affects <= 5.2.6 Patched in 5.2.7
  2. 2026-08-13 CVE-2026-73403 Missing Authorization Affects <= 5.2.6 Patched in 5.2.7
  3. 2026-07-27 CVE-2026-16736 Missing Authorization Affects <= 5.2.5 Patched in 5.2.6
  4. 2026-06-26 CVE-2026-11966 Authorization Bypass Through User-Controlled Key Affects <= 5.2.2 Patched in 5.2.3
  5. 2026-06-26 CVE-2026-11961 Improper Privilege Management Affects <= 5.2.2 Patched in 5.2.3
  6. 2026-06-25 CVE-2026-1869 Missing Authorization Affects <= 5.2.0 Patched in 5.2.1
  7. 2026-06-22 CVE-2026-52701 Missing Authorization Affects <= 5.2.2 Patched in 5.2.3
  8. 2026-06-22 CVE-2026-11964 Improper Authentication Affects <= 5.2.1 Patched in 5.2.2
  9. 2026-06-22 CVE-2026-11963 Authorization Bypass Through User-Controlled Key Affects <= 5.2.1 Patched in 5.2.2
  10. 2026-06-11 CVE-2026-11965 Client-Side Enforcement of Server-Side Security Affects <= 5.1.0 Patched in 5.2.0
  11. 2026-05-28 CVE-2026-25425 Missing Authorization Affects <= 5.1.2 Patched in 5.1.3
  12. 2026-05-27 CVE-2026-7651 Authorization Bypass Through User-Controlled Key Affects <= 5.1.5 Patched in 5.1.6
  13. 2026-05-13 CVE-2026-6145 Missing Authorization Affects <= 5.1.5 Patched in 5.1.6
  14. 2026-05-04 CVE-2026-3601 Missing Authorization Affects <= 5.1.4 Patched in 5.1.5
  15. 2026-04-13 CVE-2026-6203 URL Redirection to Untrusted Site ('Open Redirect') Affects <= 5.1.4 Patched in 5.1.5
  16. 2026-04-09 CVE-2026-42652 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 5.1.5 Patched in 5.1.6
  17. 2026-04-07 CVE-2026-1865 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 5.1.2 Patched in 5.1.3
  18. 2026-03-23 CVE-2026-4056 Missing Authorization Affects <= 5.1.4 Patched in 5.1.5
  19. 2026-03-23 CVE-2026-32488 Incorrect Privilege Assignment Affects <= 4.4.9 Patched in 5.1.3
  20. 2026-03-02 CVE-2026-1492 Improper Privilege Management Affects <= 5.1.2 Patched in 5.1.3
  21. 2026-02-25 CVE-2026-2356 Improper Access Control Affects <= 5.1.2 Patched in 5.1.3
  22. 2026-02-25 CVE-2026-1779 Authentication Bypass Using an Alternate Path or Channel Affects <= 5.1.2 Patched in 5.1.3
  23. 2026-01-21 CVE-2025-67956 Missing Authorization Affects <= 4.4.6 Patched in 4.4.7
  24. 2026-01-09 CVE-2025-14976 Cross-Site Request Forgery (CSRF) Affects <= 4.4.8 Patched in 4.4.9
  25. 2026-01-08 CVE-2026-24353 Improper Control of Generation of Code ('Code Injection') Affects <= 4.4.9 Patched in 5.0
  26. 2025-12-15 CVE-2025-13367 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.4.6 Patched in 4.4.7
  27. 2025-09-05 CVE-2025-9085 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 4.3.0 Patched in 4.4.0
  28. 2025-07-21 CVE-2025-6831 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.2.4 Patched in 4.3.0
  29. 2025-05-05 CVE-2025-3281 Authorization Bypass Through User-Controlled Key Affects <= 4.2.1 Patched in 4.2.2
  30. 2025-04-22 CVE-2025-39400 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.1.5 Patched in 4.2.0
  31. 2025-04-11 CVE-2025-3292 Authorization Bypass Through User-Controlled Key Affects <= 4.1.3 Patched in 4.1.4
  32. 2025-04-11 CVE-2025-3282 Authorization Bypass Through User-Controlled Key Affects <= 4.1.3 Patched in 4.1.4
  33. 2025-04-01 CVE-2025-2594 Authentication Bypass Using an Alternate Path or Channel Affects <= 4.1.2 Patched in 4.1.3
  34. 2025-03-27 CVE-2025-30899 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.0.3 Patched in 4.0.4
  35. 2025-03-24 CVE-2025-2563 Improper Privilege Management Affects <= 4.1.1 Patched in 4.1.2
  36. 2025-02-27 CVE-2025-1511 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.0.4 Patched in 4.1.0
  37. 2024-05-31 CVE-2024-4958 Missing Authorization Affects <= 3.2.0.1 Patched in 3.2.1
  38. 2024-04-19 CVE-2024-2417 Missing Authorization Affects <= 3.1.5 Patched in 3.2.0
  39. 2024-04-15 CVE-2024-3295 Missing Authorization Affects <= 3.1.5 Patched in 3.2.0
  40. 2024-03-06 CVE-2024-1720 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.1.4 Patched in 3.1.5
  41. 2023-10-16 CVE-2023-5228 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.0.4.1 Patched in 3.0.4.2
  42. 2023-07-04 CVE-2023-3342 Unrestricted Upload of File with Dangerous Type Affects <= 3.0.2 Patched in 3.0.2.1
  43. 2023-06-29 CVE-2023-3343 Deserialization of Untrusted Data Affects <= 3.0.1 Patched in 3.0.2
  44. 2023-04-06 CVE-2023-29429 Missing Authorization Affects <= 2.3.2.1 Patched in 2.3.3
  45. 2023-03-21 CVE-2023-27459 Deserialization of Untrusted Data Affects <= 2.3.2.1 Patched in 2.3.3
  46. 2023-01-20 CVE-2023-23987 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.3.0 Patched in 2.3.1
  47. 2022-11-21 CVE-2022-3912 Unrestricted Upload of File with Dangerous Type Affects <= 2.2.4 Patched in 2.2.41
  48. 2019-01-09 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.5.5 Patched in 1.5.6

Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.

CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.

Behavioral tests

via WP Hive

Automated install-time checks, tested on PHP 8.1.12 · WP 7.0.1

Low memory footprint
Low page-speed impact
Runs on latest PHP + WP
No PHP errors
No JS errors
Activates cleanly
No resource errors
No external HTTP errors
Optimized database use
Frequently updated

Languages

via translate.wordpress.org

Translated into 17 languages, 1 at 90% or more

Lao 98%
Korean 66%
Swedish 44%
Dutch 34%
Russian 31%
Spanish (Spain) 24%
German 23%
Portuguese (Brazil) 23%
Japanese 21%
Czech 19%
French (France) 19%
German (Formal) 19%
Chinese (China) 17%
Ukrainian 17%
Persian 11%
Italian 4%
Spanish (Mexico) 1%

Growth timeline

Install-tier crossings we have observed, and how long each tier took to outgrow

  1. 2026-06-28 60K+ → 50K+ down after 353 days in tier
  2. 2025-07-10 70K+ → 60K+ down after 4 days in tier
  3. 2025-07-06 60K+ → 70K+ up after 2 days in tier
  4. 2025-07-04 70K+ → 60K+ down after 2 days in tier
  5. 2025-07-02 60K+ → 70K+ up after 2 days in tier
  6. 2025-06-30 70K+ → 60K+ down after 63 days in tier
  7. 2025-04-28 60K+ → 70K+ up after 301 days in tier
  8. 2024-07-01 70K+ → 60K+ down after 76 days in tier

Competes with

The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).

Compare head to head →

Embed this report card

Drop a live Pulse card for User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder into a readme, a review or a deck. It updates itself.

<iframe src="https://plugins.wpmayor.com/embed/user-registration" width="480" height="300" style="border:0" loading="lazy" title="User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder — Plugin Pulse"></iframe>
Preview card ↗

User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder: 50K+ active installs, 4.8★ (828 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/user-registration