Plugin Pulse
← Pulse

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress

by properfraction · eCommerce

Also makes 4 other plugins · 230K+ installs across the portfolio →

Setup paid membership, accept payment, sell subscription & digital product, paywall, create login & registration form, user profile & member directory

How scoring works →
76 Health · B
Maintenance 100/100
Rating quality 53/100
Support 70/100

76 health vs 68 average across 5,563 eCommerce plugins

Directory ranking optimization

How it's scored →

How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.

93 / 100

Excellent listing optimization

Biggest win: Rating quality

Update recency 100/100
WP compatibility 100/100
Rating quality 63/100
Listing tuning 100/100
Support resolution 100/100

To rank higher: Lift the average: resolve the issues driving the low reviews.

Get the full rank-higher report →

Daily downloads

Since 2022-10-05 · 1,422 days · wp.org + Plugin Pulse archive

+61% vs prior 30d
1.4KDownloads · Aug 26

30-day downloads

Rolling 30-day volume · peaks are release surges

107.4K

now · peak 346.9K

106.9K30d downloads · Aug 26

Directory rank vs rivals

wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you

Paid Membership Plug · #348 you Ultimate Member · #264 User Registration & · #713 User Frontend · #1331

Rating trend

Star average over time · dips mark rough releases

3.1Stars · Aug 26

Update activity

How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.

1.1Kper 1k installs · Aug 26

Release cadence

Actively maintained
from wp.org release tags

How often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.

14

releases in the last 12 months

2mo ago

latest release · v4.16.19

215

tagged releases on record

Recent releases

4.16.19 · 2mo ago4.16.18 · 2mo ago4.16.17 · 3mo ago4.16.16 · 3mo ago4.16.15 · 4mo ago4.16.14 · 5mo ago4.16.13 · 5mo ago4.16.12 · 6mo ago4.16.11 · 6mo ago4.16.10 · 6mo ago4.16.9 · 7mo ago4.16.8 · 9mo ago4.16.7 · 10mo ago4.16.6 · 11mo ago

What its installed base runs

via wordpress.org

Share of active installs on each version of this plugin. Green is the current release; a big slice on older versions is a user base that has stopped updating.

v4.16 49%
v2.2 19%
v4.15 9.5%
Older / other versions 23%

Estimated active installs

The public count shows “100K+”. Our estimate pins where the real number sits.

tracked estimate
100K–200K ≈190K

Refined from the date this plugin crossed into its current band.

Install history · since 2015-03-21 · 1,485 observations

100KInstalls · Aug 26

Estimated value

What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.

Est. annual revenue

N/A

Est. acquisition value

N/A

No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price.

Details

Version
4.17.1
Last updated
9d ago
Added
2013-01-14 · 13 yrs old
Requires WP
6.0
Tested up to
7.1
Requires PHP
7.4

Recent reviews

All reviews on wp.org ↗
  1. 1question
    2mo ago

    Hi, Big thanks for this plugin : )

    Read on wp.org ↗
  2. jacobdreizin
    3mo ago

    My paywalled/subscription website crashed when ProfilePress pushed an update with a small error in the coding (in the part responsible for user avatar pics, of all things), but the support was very responsive, and resolved the problem on the same day, in fact within at most 5 hours of my first communication, which I was really not expecting. Thank you!

    Read on wp.org ↗
  3. mvxweb
    3mo ago

    The content restriction feature is straightforward and works reliably. Tested with different user accounts and membership levels, and access was always enforced correctly. No fuss. No confusing setup.

    Read on wp.org ↗
  4. Ryan
    4mo ago

    This is an excellent plug‑in. I’m surprised I haven’t heard about it before. Shockingly, it integrates with multiple prominent LMS platforms, including LearnDash, and the platform is very user‑friendly. So I feel I’ve got great value for money. I hope the developers or the owners keep updating and improving the plugin.

    Read on wp.org ↗
  5. negru13
    5mo ago

    This used to be WP User Avatar. Now is this bloated usless plugin. Not what I asked for.

    Read on wp.org ↗
  6. weswebmaster
    6mo ago

    We are working towards a new website, and the ProfilePress team have been extremely supportive in answering queries and even responding to feature requests. Great team! Thank you.

    Read on wp.org ↗
  7. chaney220
    7mo ago

    I was using Profile Press for a little bit but found that it just didn’t have all of the options that I needed for my customers’ profiles. I started using Ultimate Member, and it has many more features.

    Read on wp.org ↗
  8. devmickey
    7mo ago

    ​ I’ve been using ProfilePress for memberships and payments, and it has become a core part of my WordPress setup. It’s a powerful ecommerce and paid membership plugin that supports one-time and recurring payments, selling subscriptions, and restricting content behind a paywall with access to control rules. Their plugin is well documented, so everyone should be able to set it up. On top of that, it’s very flexible on the front end: you can build custom registration, login, password reset, and edit-profile forms using a drag-and-drop builder, and you can also create user profiles and member directories. What truly stands out is their team: fast responses, clear answers, and genuine willingness to think along and propose practical solutions. Special mention to Ibrahim and Collins who consistently go above and beyond with tailored fixes and implementations. They really do listen to their community and have a can-do mentality when it comes to changing the product to meet customer expectations. Overall, highly recommended for anyone building a membership site or selling digital products on WordPress. Good luck on the further development!

    Read on wp.org ↗

Latest updates

via wp.org changelog

Recent releases and news for this plugin

  1. Version 4.16.19 Add optional order creation to the Add New Customer screen. Fixed bug where suppressed email still went out. Fixed security issue where other file types (exe, msi) could be uploaded outside ProfilePress upload scope. Imp 4.16.19
  2. Version 4.16.18 Added compatibility with Yoast URL Cleanup feature. Fix security issue where non-admin user role can be passed as user role. 4.16.18
  3. Version 4.16.17 Fixed security issue a user subscription can be canceled by another user. 4.16.17
  4. Version 4.16.16 Pro: Paddle addon . Added password visibility icons to the password reset handler form fields 4.16.16
  5. Version 4.16.15 Pro: Brevo addon . Pro: Auto-Renewal Checkbox addon . Added filters to the test mode notice and checkout username. Added membership conditions to Elementor display rules. See the changelog file for full change log inform 4.16.15
  6. Version 4.17.0 Premium: Added Pay What You Want addon . Added Subscription Payment Failed email notification. Fixed Stripe bug where email change caused checkout failure. Fixed fatal error when price has a currency symbol or thousands 4.17.0

Known vulnerabilities

via Wordfence Intelligence

47 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.

  1. 2026-08-15 CVE-2026-18385 Improper Control of Generation of Code ('Code Injection') Affects <= 4.16.19 Patched in 4.17.0
  2. 2026-07-16 CVE-2026-13352 Unrestricted Upload of File with Dangerous Type Affects <= 4.16.18 Patched in 4.16.19
  3. 2026-07-03 CVE-2026-12497 Improper Privilege Management Affects <= 4.16.17 Patched in 4.16.18
  4. 2026-06-06 CVE-2026-10820 Authorization Bypass Through User-Controlled Key Affects <= 4.16.16 Patched in 4.16.17
  5. 2026-04-23 CVE-2026-41556 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.16.13 Patched in 4.16.14
  6. 2026-04-15 CVE-2026-4949 Missing Authorization Affects <= 4.16.12 Patched in 4.16.13
  7. 2026-04-03 CVE-2026-3309 Improper Control of Generation of Code ('Code Injection') Affects <= 4.16.11 Patched in 4.16.12
  8. 2026-04-03 CVE-2026-3445 Missing Authorization Affects <= 4.16.11 Patched in 4.16.12
  9. 2026-03-10 CVE-2026-3453 Authorization Bypass Through User-Controlled Key Affects <= 4.16.11 Patched in 4.16.12
  10. 2025-12-08 CVE-2025-13642 Improper Control of Generation of Code ('Code Injection') Affects <= 4.16.7 Patched in 4.16.8
  11. 2025-08-15 CVE-2025-8878 Improper Control of Generation of Code ('Code Injection') Affects <= 4.16.4 Patched in 4.16.5
  12. 2025-01-23 CVE-2024-13120 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.15.19 Patched in 4.15.20
  13. 2025-01-23 CVE-2024-13121 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.15.19 Patched in 4.15.20
  14. 2025-01-23 CVE-2024-13119 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.15.19 Patched in 4.15.20
  15. 2024-11-26 CVE-2024-11083 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 4.15.18 Patched in 4.15.19
  16. 2024-11-21 CVE-2024-10517 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.15.14 Patched in 4.15.15
  17. 2024-11-21 CVE-2024-10518 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.15.14 Patched in 4.15.15
  18. 2024-05-22 CVE-2024-2861 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.15.8 Patched in 4.15.9
  19. 2024-04-11 CVE-2024-2867 Improper Input Validation Affects <= 4.15.4 Patched in 4.15.5
  20. 2024-04-09 CVE-2024-3210 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.15.5 Patched in 4.15.6
  21. 2024-03-12 CVE-2024-1535 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.15.2 Patched in 4.15.3
  22. 2024-02-23 CVE-2024-1806 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.15.1 Patched in 4.15.2
  23. 2024-02-22 CVE-2024-1409 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.15.0 Patched in 4.15.1
  24. 2024-02-19 CVE-2024-1570 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.14.4 Patched in 4.15.0
  25. 2024-02-19 CVE-2024-1519 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.14.4 Patched in 4.15.0
  26. 2024-02-19 CVE-2024-1408 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.14.4 Patched in 4.15.0
  27. 2024-02-01 CVE-2024-1046 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.14.3 Patched in 4.14.4
  28. 2023-10-02 CVE-2023-44150 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 4.13.2 Patched in 4.13.3
  29. 2023-09-09 CVE-2023-41954 Improper Input Validation Affects < 4.13.2 Patched in 4.13.2
  30. 2023-09-09 CVE-2023-41953 Cross-Site Request Forgery (CSRF) Affects < 4.13.2 Patched in 4.13.2
  31. 2023-06-23 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 4.11.0 Patched in 4.11.0
  32. 2023-03-27 CVE-2022-47444 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.5.3 Patched in 4.5.4
  33. 2023-02-21 CVE-2023-23830 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.5.4 Patched in 4.5.5
  34. 2023-02-20 CVE-2023-23820 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.5.4 Patched in 4.5.5
  35. 2023-01-20 CVE-2023-23996 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.5.3 Patched in 4.5.4
  36. 2022-12-23 CVE-2022-4697 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.5.0 Patched in 4.5.1
  37. 2022-12-23 CVE-2022-4698 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.5.0 Patched in 4.5.1
  38. 2022-12-14 CVE-2022-45083 Deserialization of Untrusted Data Affects <= 4.3.2 Patched in 4.4.0
  39. 2022-07-22 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.2.15 Patched in 3.2.16
  40. 2021-11-15 CVE-2021-24955 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 3.2.3 Patched in 3.2.3
  41. 2021-11-15 CVE-2021-24954 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 3.2.3 Patched in 3.2.3
  42. 2021-08-09 CVE-2021-24522 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.1.10 Patched in 3.1.11
  43. 2021-06-28 CVE-2021-34624 Unrestricted Upload of File with Dangerous Type Affects 3.0.0 - 3.1.3 Patched in 3.1.4
  44. 2021-06-28 CVE-2021-34622 Improper Privilege Management Affects 3.0.0 - 3.1.3 Patched in 3.1.4
  45. 2021-06-28 CVE-2021-24450 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 3.1.8 Patched in 3.1.8
  46. 2021-06-28 CVE-2021-34623 Unrestricted Upload of File with Dangerous Type Affects 3.0.0 - 3.1.3 Patched in 3.1.4
  47. 2021-06-28 CVE-2021-34621 Improper Privilege Management Affects 3.0.0 - 3.1.3 Patched in 3.1.4

Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.

CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.

Behavioral tests

via WP Hive

Automated install-time checks, tested on PHP 8.1.12 · WP 7.0

Low memory footprint
Low page-speed impact
Runs on latest PHP + WP
No PHP errors
No JS errors
Activates cleanly
No resource errors
No external HTTP errors
Optimized database use
Frequently updated

Languages

via translate.wordpress.org

Translated into 35 languages, 5 at 90% or more

Dutch 100%
Dutch (Formal) 100%
Korean 99%
Lao 99%
Swedish 90%
Russian 86%
Spanish (Chile) 80%
Spanish (Spain) 69%
Ukrainian 60%
Spanish (Colombia) 26%
Spanish (Ecuador) 26%
Turkish 23%
Japanese 19%
German (Formal) 9%
German 8%
French (France) 7%
Dutch (Belgium) 6%
English (UK) 3%
Italian 2%
Afrikaans 1%
Albanian 1%
Bulgarian 1%
Cebuano 1%
Chinese (China) 1%

Plus 11 more locales with partial translations.

Growth timeline

Install-tier crossings we have observed, and how long each tier took to outgrow

  1. 2025-06-14 200K+ → 100K+ down after 651 days in tier
  2. 2023-09-02 300K+ → 200K+ down

Competes with

The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).

Compare head to head →

Embed this report card

Drop a live Pulse card for Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress into a readme, a review or a deck. It updates itself.

<iframe src="https://plugins.wpmayor.com/embed/wp-user-avatar" width="480" height="300" style="border:0" loading="lazy" title="Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress — Plugin Pulse"></iframe>
Preview card ↗

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress: 100K+ active installs, 3.1★ (937 reviews). Plugin Pulse (WP Mayor), as of 2026-08-26. https://plugins.wpmayor.com/plugin/wp-user-avatar