TECHNOLOGIES: MEMBERSTACK

Memberstack Integration Security Review

Memberstack’s own documentation admits its front-end gating can be bypassed if a visitor already knows a protected URL. We test your plans, keys, custom fields and webhooks, not Memberstack’s platform. CREST-certified testers, fixed price from £2,080 for a 1-day single-integration scope, quoted within 24 hours.

  • Unlimited retesting
  • Unlimited pre-retesting
  • No hidden fees
Accredited & recognised
Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified Crown Commercial Service supplier UK Cyber Security Council member
CREST
Approved Provider
10
Memberstack Test Areas
FREE
Retest Until Closed
24h
Scope to Active Test
CLIENT REFERENCE
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
SquareOneImran SaghirProject Lead, SquareOneRead the SquareOne case study →
CLIENT REFERENCE
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
CelloriDan WilcocksonFounder, CelloriRead the Cellori case study →
See all case studies →
WHY IT MATTERS
Redirect

Memberstack’s Gated Content feature checks a member’s plan in the browser and sends anyone without it to an Access Denied URL. The page, folder or file behind that redirect is still served at its original address.

Why Memberstack gaps sit in your redirects, keys and custom fields, not the platform

A Memberstack integration runs on two keys that are meant to stay apart. The DOM package that runs in the browser is initialised with a publishable public key, and every session, login and signup flow it drives, whether by email and password, a social provider such as Google, or a passwordless link, happens client-side against that key. The Admin package that actually manages members, plans and Metadata needs a separate secret key, which Memberstack’s own documentation says has to stay on the server, and a third secret again for verifying webhooks. We test whether all three actually stayed where they were meant to.

Where those keys don’t reach, Memberstack’s gating features do the rest, and here the vendor is explicit about the limit. Gated Content restricts a page, a folder or a CMS collection to members on a chosen plan by checking that plan in the browser and redirecting anyone without it, and data-ms-content shows or hides individual elements the same way, based on a plan, a free trial, a custom field or Metadata. Memberstack’s documentation states plainly that this front-end authorisation isn’t a fully secure solution: if the check fails to load, or a visitor already knows the exact URL, the content behind it is still there to be reached. Hosted Content exists as the stronger alternative, serving HTML or a link only once access is actually confirmed, and we test whether the content that needed it got it.

The rest of the integration sits in ordinary application code: whether a Visible Custom Field, which any logged-in member can edit from their own browser console, is ever trusted for something Metadata should hold instead; whether a webhook receiver checks the Svix signature Memberstack sends before acting on an event; and whether the Admin package’s secret key reaches further than the server code that calls it. None of this is a fault in Memberstack itself. It is what a team building on top of it, inside a Webflow site or any other front end, still has to get right.

SCOPE

What we pen test on a Memberstack integration

MS-01

Public and Secret Key Separation

Memberstack’s DOM package is initialised in the browser with a publishable public key, while the Admin package that performs CRUD operations on members and plans uses a secret key that Memberstack’s own documentation says must stay on the server. We check whether the secret key, or the separate webhook signing secret used to verify Svix deliveries, has reached client-side bundles, a public repository or a frontend environment variable, and what an exposed public key alone actually allows an attacker to do compared with a leaked secret key.

MS-02

Session Token and JWT Verification

Server-side code that needs to trust a Memberstack session is expected to verify the member’s token through the Admin package, either with the Node.js library or by calling the REST endpoint at admin.memberstack.com/members/verify-token with the secret key in the X-API-KEY header, rather than reading the token’s claims without checking them. We test whether every route that gates access on the server actually calls this verification, or instead trusts a member ID or plan taken from the client-side getCurrentMember() call or a request parameter.

MS-03

Visible Custom Field Tampering

Visible custom fields, wired up with the data-ms-member attribute, are read-write from the browser by design, and Memberstack’s own documentation states that a logged-in member can open the console and script a change to any of them, including a field meant to record a role or tier. We test whether your application ever treats a visible custom field’s value as an access-control decision, since Memberstack enforces none of that meaning on your behalf.

MS-04

Metadata Used for Access Flags

Metadata sits behind the Admin package’s secret key: it can only be written from the backend, though the value is still readable on the frontend once retrieved through the DOM package. We test whether your integration actually stores administrative states, external IDs and clearance flags in Metadata rather than a visible custom field, and whether any code path relies on Metadata’s frontend readability to make a decision the field was never meant to gate on its own.

MS-05

Gated Pages, Folders and CMS Collections

Memberstack’s Gated Content feature restricts a page, a folder or a CMS collection to members on a chosen plan by checking that plan in the browser and sending anyone without it to an Access Denied URL, using a Starts with or Equal to match against the page path. Memberstack’s own documentation states plainly that this isn’t a fully secure solution: if the check fails to load, or a visitor already knows the exact URL, the content behind it is still reachable. We test every Restricted URL rule against direct navigation and cached responses, not just the redirect a browser follows on a normal visit.

MS-06

Element-Level Content Hiding

Individual elements are shown or hidden with the data-ms-content attribute, checked against a member’s plan, free trial status, metadata or custom fields, and Memberstack recommends adding a CSS snippet that hides the element by default so it never flashes into view before the check runs. We test whether the underlying markup, an API response or the page’s initial HTML still carries the hidden content itself, since a CSS or JavaScript hide changes what a visitor sees, not what was actually sent to their browser.

MS-07

Hosted Content for Downloads and Links

Memberstack’s Hosted Content feature is built for cases where a redirect is not enough: it is designed to securely serve HTML or populate a link only once a member’s access has actually been confirmed, rather than relying on a page simply not being linked to. We test whether the downloads, gated files or partner links your integration exposes use this mechanism or a static URL that a member on the wrong plan, or no plan at all, can reach directly.

MS-08

Webhook Signature Verification

Memberstack delivers webhooks through Svix, sending SVIX-ID, SVIX-SIGNATURE and SVIX-TIMESTAMP headers that a receiver is meant to check with the Admin package’s verifyWebhookSignature() method, the webhook secret from the dashboard, and a tolerance window for a stale timestamp. We test whether your webhook endpoint actually verifies that signature on every request, rejects anything outside the tolerance window, and handles a duplicate delivery safely rather than acting on any POST that arrives.

MS-09

Admin API Access to Members and Plans

The Admin package, available for Node.js and as a REST API against admin.memberstack.com, gives full create, read, update and delete access to members and the ability to manage a member’s plans, authenticated with the secret key and rate-limited to 25 requests per second. We review the server-side code that calls it for any endpoint that exposes member deletion, plan changes or bulk listing to a request an ordinary member could send, and for what happens once that rate limit is hit.

MS-10

Signup and Login Flow Handling

The DOM package handles member signup and login with email and password, social providers including Google and Facebook, and passwordless sign-in, wired into a page through Memberstack’s own data-attribute-driven forms rather than a form your backend controls. We test how your integration handles the redirect after signup or login, whether a value submitted at signup can land in a Visible Custom Field it was never meant to reach, and whether every authentication method enabled in your dashboard is actually intended to be live.

OUR PROCESS

Memberstack Integration Security Review: From Scope to Attestation

01

Scope and Key Mapping

We agree which plans, gated pages, content groups, webhooks and admin integrations are in scope, and map every public key, secret key and webhook secret in use before testing begins.

02

Provision Test Members Across Plans

We work from test member accounts covering every plan and free-trial state configured in your Memberstack instance, so every gating and metadata check runs against a real member.

03

Gating, Token and Webhook Exploitation

CREST-certified testers attempt to reach gated pages, elements and hosted content directly, tamper with visible custom fields, and test webhook and admin key handling.

04

Reporting and Retest

Executive summary, technical report with CVSS scores and reproduction steps, a walkthrough call, and a free retest once fixes are in place.

CREDENTIALS

Verified Accreditations Auditors Accept

Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.

GET YOUR QUOTE

Get a CREST Memberstack pen test quote in 24 hours

A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.

  • CREST and IASME accredited. Testing your auditors and clients already recognise.
  • Fast-track testing within 24 hours where required. Free retest of every fix included.
  • Live findings via your client portal, not a four-week PDF.
  • Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
What clients say
There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.
CelloriDan WilcocksonFounder, Cellori

Under NDA Further named references available on a scoping call.

What happens next
  1. We reply within one business day with a fixed-price quote from a named CREST assessor.
  2. You approve the scope and we book a start date, usually within 24 hours.
  3. Live findings land in your client portal as we test, with a free retest of every fix.
Accredited & recognised
CREST member Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified UK Cyber Security Council Crown Commercial Service supplier

Get your fixed pen test quote in 24 hours

⚡24h reply ✓CREST tester ↻Free retests

or book a 20-min scoping call first

We reply within one business day. Your data stays with us. No newsletter signup.

COMPLIANCE READY

Reports Mapped to Every Framework

Findings are written so your team can reference the report against each framework without translation work.

ISO 27001:2022

Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.

SOC 2 Type I & II

CC6 logical access, CC7 system operations, CC8 change management evidence.

PCI DSS

Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.

FCA SYSC

SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.

UK GDPR

Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.

Cyber Essentials Plus

Direct certification through our IASME body status, single-vendor delivery.

PRICING

Transparent Memberstack Integration Security Review Pricing

Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.

✦ ALWAYS · ON EVERY TIER · NO EXCEPTIONS ✦
✓Free retests, no time limit
✓Free rescheduling
✓No cancellation fees
✓24-hour scope to active testing
✓Live findings to client portal
✓Executive + technical report
✓60-min walkthrough call
✓Letter of attestation
SMALL / SMB
£2,080–£3,060
1 to 2 testing days

Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.

Get a fixed quote
ENTERPRISE
£4,890–£7,450
3 to 5 testing days

Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.

Get a fixed quote

Full UK pen test cost guide

WHY EJN LABS

What You Get From Memberstack Integration Security Review

Six concrete differentiators competitors don’t all match.

CREST-Certified Testers, Verifiable

Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.

24-Hour Startup, Where Required

From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.

Live Findings, Not 4-Week PDFs

Critical issues reported during testing through your client portal. Your team remediates while testing continues.

Audit-Ready Reports

Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).

Free Retests, Standard

Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.

UK-Based CREST Testers

Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.

FAQ

Frequently Asked

What access do you need to test our Memberstack integration?

A test member account on a plan you control, ideally one for each plan or content group configured, plus your public key so we can call the DOM package the way your site does. Visibility of any server-side code that calls the Admin package, and of your webhook receiver, speeds up coverage but is not required for black-box testing.

Does this touch our live members or production Memberstack app?

No. We test against a staging Memberstack app or test member accounts you provision, on plans that mirror production, whichever is available. If only a shared app exists, we agree data-handling rules and scope testing to test accounts before it starts.

How long does a Memberstack integration review take?

A single-integration scope like this one starts at 1 testing day, with results delivered around 5 working days after kickoff. Additional plans, gated content groups or a custom admin panel built on the Admin package add testing days; we confirm exact days once we see your setup.

Is Memberstack tested differently depending on how it’s hosted?

No separate self-hosted version exists to compare it against. Every Memberstack app runs on infrastructure Memberstack operates itself, so testing concentrates on your public and secret key handling, your gated content configuration, your custom fields and metadata, and your webhook and admin integration code, not Memberstack’s hosting.

What is out of scope?

Memberstack’s own platform, dashboard and hosting infrastructure are out of scope, along with any Memberstack feature your integration has not enabled. We test the plans, keys, gating rules, custom fields, metadata and webhooks your team has configured and built around them.

Does Memberstack have a policy for reporting security issues?

Yes. Memberstack states that it investigates reported security issues and asks that a security bug be emailed to its support address rather than disclosed publicly until it is addressed, and it holds SOC 2 certification covering its own infrastructure. That covers Memberstack’s platform, not your integration; we confirm Memberstack’s current customer-testing terms with you during scoping before any testing starts.

We rely on Memberstack’s Gated Content redirects to protect pages. Is that enough on its own?

Not on its own, by Memberstack’s own account: its documentation states that front-end gating isn’t a fully secure solution and that content behind a Restricted URL rule stays reachable if a visitor already knows the exact address. We test what actually protects the page behind that redirect, and whether Memberstack’s Hosted Content feature would close the gap for anything genuinely sensitive.

Do you test our webhook endpoint specifically?

Yes. We check that it verifies the Svix signature Memberstack sends on every request, using the webhook secret and the tolerance window your code allows, and that it does not process the same event twice on a retried delivery.

EXPLORE EVERY SERVICE

20+ CREST-accredited testing services in one place

Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.

Penetration testing services
READY TO START

Get a fixed price for your Memberstack integration

Memberstack’s own documentation admits its front-end gating can be bypassed if a visitor already knows a protected URL. We test your plans, keys, custom fields and webhooks, not Memberstack’s platform. CREST-certified testers, fixed price from £2,080 for a 1-day single-integration scope, quoted within 24 hours.