TECHNOLOGIES: MEMBERPRESS

MemberPress Penetration Testing

A MemberPress rule opens content once any one of its conditions matches, and skips entirely for admin accounts. We test which conditions, roles and gateways actually control access on your site. CREST-certified testers, fixed price from £2,060 for a 2-day single-site scope, quoted within 24 hours.

  • Unlimited retesting
  • Unlimited pre-retesting
  • No hidden fees
Accredited & recognised
Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified Crown Commercial Service supplier UK Cyber Security Council member
CREST
Approved Provider
10
MemberPress Test Areas
FREE
Retest Until Closed
24h
Scope to Active Test
CLIENT REFERENCE
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
SquareOneImran SaghirProject Lead, SquareOneRead the SquareOne case study →
CLIENT REFERENCE
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
CelloriDan WilcocksonFounder, CelloriRead the Cellori case study →
See all case studies →
WHY IT MATTERS
6

MemberPress rules can each be set to one of six conditions, Product, Member, Role, Login State, Capability or Course Completed, and a rule holding several of them grants access the moment any single one matches.

Why MemberPress access depends on which rule condition actually matches

MemberPress protects content with rules checked against a Product, Member, Role, Login State, Capability or Course Completed condition, and a rule with more than one condition only needs a single one of them satisfied before access is granted. MemberPress’s own documentation also states that it ignores every rule for a user with administrative rights, so the accounts that hold that level of access on your site sit outside the rule engine entirely. We test whether the conditions attached to each rule match what your business actually intended, and which accounts on your site carry enough capability to fall into that admin exemption.

Drip and expiration settings sit inside the same rule, releasing or withdrawing access on a fixed date, on registration, or after a member buys a specific membership, and MemberPress’s own dripping and expiring content documentation notes that rule-level drip settings take priority over a course’s own built-in dripping wherever the two conflict. Memberships can also be organised into groups so members can upgrade or downgrade between tiers, and on a switch MemberPress cancels the current subscription and opens a new one rather than running both side by side. We test whether a drip trigger, an expiry date or a mid-switch subscription state can be used to reach content earlier, later or on a tier the account never actually paid for.

Payments run through Stripe, PayPal, Square or Authorize.net, and MemberPress activates a subscription once the connected gateway confirms the transaction rather than deciding that itself, with Stripe Connect provisioning its own webhook endpoint on your domain to receive that confirmation. A separate Developer Tools add-on adds a REST API and outbound webhooks, authenticated with a single MEMBERPRESS-API-KEY header rather than a per-user WordPress login. We test whether that gateway confirmation, webhook endpoint and API key genuinely enforce the same boundaries as the WordPress site they sit on top of.

SCOPE

What we pen test on a MemberPress site

MP-01

Rule Condition and Administrator Bypass Coverage

Every MemberPress rule can be set to a Product, Member, Role, Login State, Capability or Course Completed condition, and a rule holding several of them grants access the moment any single condition is met rather than requiring all of them. MemberPress also ignores every rule once the current user holds administrative rights, so we test which accounts on your site actually carry that level of access and whether each rule’s conditions match what the content was meant to allow.

MP-02

Custom URI and Non-Standard Content Rendering

Standard MemberPress rules protect content rendered through WordPress’s own content function, and MemberPress’s documentation flags that some themes, page builders and other plugins render their output outside of it, leaving that content unprotected even with a rule attached. We test every page builder section, custom post type and Custom URI rule on your site for content a standard rule was never actually able to reach.

MP-03

Drip and Expiration Trigger Timing

A rule’s drip or expiration setting can trigger on member registration, a fixed date, or the purchase of any or a specific membership, and MemberPress applies rule-level drip settings ahead of a course’s own built-in dripping wherever the two conflict. Where a site delivers its courses through LearnDash, one of the course platforms MemberPress lists as a known integration rather than MemberPress’s own course builder, we test whether a drip or expiry date on either plugin can be bypassed by requesting the protected page, lesson or file directly.

MP-04

Group Upgrade and Downgrade Transitions

Memberships placed in a MemberPress group let a member upgrade or downgrade between tiers, and each membership can only belong to one group. On a switch, MemberPress cancels and expires the current subscription while creating a new one for the membership just chosen, so we test whether that cancel-then-create sequence can be timed or interrupted to hold access to both tiers, or to reach a tier the account never actually paid for.

MP-05

Payment Gateway Confirmation for Online Subscriptions

For Stripe, PayPal, Square and Authorize.net registrations, the processor collects card details on its own hosted form and returns the transaction result to MemberPress, which then creates the transaction and activates or deactivates the subscription based on that result rather than anything sent by the browser. We test whether that confirmation is genuinely verified server-side for every gateway your site has enabled.

MP-06

Stripe Connect Webhook Endpoint Handling

Connecting Stripe through MemberPress provisions a webhook endpoint on your own domain and manages its secret and publishable keys automatically once the OAuth connection completes. We test whether that webhook endpoint verifies the authenticity of the events it receives before trusting the transaction or subscription data those events carry.

MP-07

Offline Payment Completion Setting

The Admin Must Manually Complete Transactions option is disabled by default, so an offline payment transaction is marked Complete and its subscription activated immediately rather than waiting for you to confirm the payment arrived. We test which of these two states your site is actually configured for, and whether a member can reach paid content through the offline payment path before you have been paid.

MP-08

Coupon Usage Limits and Membership Scope

A coupon’s Usage Count, Usage Limit Per User and membership-specific discount settings decide how many times it can be redeemed and against which memberships, and a coupon can also be auto-populated onto a registration page through a URL parameter. We test whether those usage limits are enforced server-side and whether a URL-parameter coupon can be applied to a membership outside the one it was actually configured for.

MP-09

Developer Tools REST API Key Scope

The Developer Tools add-on adds a REST API that can list, create, update and delete Members, Transactions, Rules and other objects at endpoints such as wp-json/mp/v1/members, authenticated with a single MEMBERPRESS-API-KEY header rather than a per-user login. We test whether that key is scoped and restricted to the access your integrations actually need, and whether every endpoint enforces the same authorisation the admin dashboard does.

MP-10

WordPress User Creation and Multiple Subscriptions

MemberPress creates a WordPress user account the first time a person registers, and the same account can hold several active subscriptions to different memberships at once, all listed on one profile. We test how that shared account, its default role and its combined set of subscriptions interact with your rules, so access granted by one membership cannot be read as access to another.

OUR PROCESS

MemberPress Penetration Testing: From Scope to Attestation

01

Scope and Access

We agree which memberships, groups and payment gateways are in scope, plus test accounts for a guest, a member on at least two membership tiers, and a site administrator.

02

Rule and Gateway Mapping

We map every rule’s conditions, drip and expiration settings against your membership and group structure, and catalogue the payment gateways, coupons and any Developer Tools API keys configured on the site.

03

Manual Testing

A CREST-certified tester manually tests rule enforcement, drip and expiration timing, group upgrade and downgrade transitions, payment gateway confirmation and the REST API, chaining findings where they compound.

04

Attestation and Retest

You get a technical report with CVSS scores and reproduction steps, a walkthrough call, a free retest once fixes are deployed, and an attestation letter for auditors.

CREDENTIALS

Verified Accreditations Auditors Accept

Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.

GET YOUR QUOTE

Get a CREST MemberPress pen test quote in 24 hours

A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.

  • CREST and IASME accredited. Testing your auditors and clients already recognise.
  • Fast-track testing within 24 hours where required. Free retest of every fix included.
  • Live findings via your client portal, not a four-week PDF.
  • Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
What clients say
There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.
CelloriDan WilcocksonFounder, Cellori

Under NDA Further named references available on a scoping call.

What happens next
  1. We reply within one business day with a fixed-price quote from a named CREST assessor.
  2. You approve the scope and we book a start date, usually within 24 hours.
  3. Live findings land in your client portal as we test, with a free retest of every fix.
Accredited & recognised
CREST member Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified UK Cyber Security Council Crown Commercial Service supplier

Get your fixed pen test quote in 24 hours

⚡24h reply ✓CREST tester ↻Free retests

or book a 20-min scoping call first

We reply within one business day. Your data stays with us. No newsletter signup.

COMPLIANCE READY

Reports Mapped to Every Framework

Findings are written so your team can reference the report against each framework without translation work.

ISO 27001:2022

Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.

SOC 2 Type I & II

CC6 logical access, CC7 system operations, CC8 change management evidence.

PCI DSS

Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.

FCA SYSC

SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.

UK GDPR

Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.

Cyber Essentials Plus

Direct certification through our IASME body status, single-vendor delivery.

PRICING

Transparent MemberPress Penetration Testing Pricing

Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.

✦ ALWAYS · ON EVERY TIER · NO EXCEPTIONS ✦
✓Free retests, no time limit
✓Free rescheduling
✓No cancellation fees
✓24-hour scope to active testing
✓Live findings to client portal
✓Executive + technical report
✓60-min walkthrough call
✓Letter of attestation
SMALL / SMB
£2,060–£3,030
2 to 3 testing days

Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.

Get a fixed quote
ENTERPRISE
£4,840–£7,370
5 to 7 testing days

Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.

Get a fixed quote

Full UK pen test cost guide

WHY EJN LABS

What You Get From MemberPress Penetration Testing

Six concrete differentiators competitors don’t all match.

CREST-Certified Testers, Verifiable

Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.

24-Hour Startup, Where Required

From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.

Live Findings, Not 4-Week PDFs

Critical issues reported during testing through your client portal. Your team remediates while testing continues.

Audit-Ready Reports

Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).

Free Retests, Standard

Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.

UK-Based CREST Testers

Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.

FAQ

Frequently Asked

What access do you need to test our MemberPress site?

We need at least one member account on each membership tier you want tested, ideally including a tier inside a group so we can test upgrade and downgrade paths, plus a site administrator account. If Stripe, PayPal, Square or Authorize.net is in scope, a way to complete a real or sandboxed payment speeds up testing of the gateway confirmation flow.

Will testing touch our live member data or live payments?

We test whichever environment you give us access to. If that is production, we agree exclusions upfront, such as which coupons, card payments or member emails to avoid, and we do not complete real transactions or alter live subscriptions without that agreement in writing.

How long does a MemberPress penetration test take?

A single MemberPress site sits in our 2-day single-site scope, with a report typically landing around 5 working days after kickoff. A site with several connected plugins, multiple payment gateways, corporate accounts or a large group structure moves into a wider scope with more testing days.

Do you test just the MemberPress plugin, or the whole WordPress site?

MemberPress runs on your own WordPress installation, so this scope covers the plugin’s rules, memberships, payments and REST API rather than the underlying server or hosting. A full WordPress build, its other plugins and its hosting are covered by our wider WordPress penetration testing, which we can scope alongside this test.

What is out of scope for a single-site MemberPress test?

Infrastructure-level issues in your WordPress hosting, server or network are out of scope for this test and covered by our cloud penetration testing service instead. A payment gateway’s own platform, such as Stripe or PayPal, is also out of scope; we test how your site’s MemberPress integration handles it, not the gateway itself.

Does MemberPress have a customer penetration-testing or disclosure policy we need to follow?

No separate customer notification process applies to testing your own installation, since MemberPress is a plugin that runs on your own WordPress site rather than a shared, MemberPress-hosted service. Your WordPress hosting provider may have its own testing policy, and MemberPress.com itself handles licence activation and the Stripe Connect handshake, so we confirm current terms with your host and with MemberPress during scoping.

Do you need our source code or plugin list?

No. Testing is black-box against the running site by default. Telling us which payment gateways, coupons, groups and add-ons such as Developer Tools or Courses are active in advance helps us scope realistic test accounts, and a grey-box option covering specific custom rule code or REST API integrations is available if you want deeper coverage.

Can you test coupons and payment gateways without disrupting real members?

Yes. We use the test accounts and gateway sandbox or test-mode credentials you provide to attempt registrations, coupon redemptions and upgrade or downgrade transitions, so real member subscriptions and live transactions are not touched unless you specifically ask us to test against production under agreed exclusions.

EXPLORE EVERY SERVICE

20+ CREST-accredited testing services in one place

Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.

Penetration testing services
READY TO START

Get a fixed price for your MemberPress site

A MemberPress rule opens content once any one of its conditions matches, and skips entirely for admin accounts. We test which conditions, roles and gateways actually control access on your site. CREST-certified testers, fixed price from £2,060 for a 2-day single-site scope, quoted within 24 hours.