About Us Team Security & Risk Analysis

wordpress.org/plugins/about-us-shortcode

The "about us" Plugin is a very simple way, to show your team member in a showroom on your site or blog post. It's have a responsive De …

60 active installs v0.1.1 PHP 5.6+ WP 5.3+ Updated Feb 13, 2020
abaoutusaboutmembersiteteam
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is About Us Team Safe to Use in 2026?

Generally Safe

Score 85/100

About Us Team has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The "about-us-shortcode" plugin version 0.1.1 exhibits a generally positive security posture based on the provided static analysis. It demonstrates good practices by avoiding dangerous functions, performing all SQL queries using prepared statements, and incorporating nonce and capability checks. Furthermore, the complete absence of known vulnerabilities in its history is a strong indicator of responsible development and maintenance. The limited attack surface, consisting solely of a single shortcode with no apparent authentication bypasses or unpatched CVEs, further strengthens this assessment.

However, a significant concern arises from the low percentage of properly escaped output. With 102 total output operations and only 16% properly escaped, there is a high probability of Cross-Site Scripting (XSS) vulnerabilities. This is a critical area of weakness that attackers could exploit to inject malicious scripts into pages where the shortcode is used. While taint analysis shows no immediate unsanitized paths, the lack of output escaping on the majority of operations creates a latent risk that could be triggered under specific, albeit currently unknown, circumstances.

In conclusion, the plugin benefits from a small attack surface, no historical vulnerabilities, and secure database interactions. Nevertheless, the widespread lack of output escaping presents a substantial risk of XSS, outweighing the positive aspects. This oversight necessitates immediate attention to ensure all output is properly sanitized before rendering.

Key Concerns

  • Low percentage of properly escaped output (16%)
Vulnerabilities
None known

About Us Team Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

About Us Team Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
86
16 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

16% escaped102 total outputs
Attack Surface

About Us Team Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[uebns] inc\uebns-shortcode.php:23
WordPress Hooks 15
actioninitabout-us-shortcode.php:35
actionplugins_loadedinc\uebns-admin.php:33
actionadmin_enqueue_scriptsinc\uebns-admin.php:36
actioninitinc\uebns-metaboxes-settings-teams.php:23
filterpost_updated_messagesinc\uebns-metaboxes-settings-teams.php:70
actionadmin_initinc\uebns-metaboxes-sidebar-settings.php:23
actionadmin_initinc\uebns-metaboxes-sidebar-shortcode.php:23
actionadmin_initinc\uebns-metaboxes-teams-content.php:23
actionsave_postinc\uebns-save-metaboxes.php:23
actionadmin_initinc\uebns-settings.php:111
actionadmin_menuinc\uebns-settings.php:221
actionmanage_uebns_posts_custom_columninc\uebns-shortcode-column.php:23
filtermanage_uebns_posts_columnsinc\uebns-shortcode-column.php:46
actionwp_enqueue_scriptsinc\uebns-user.php:23
actionwp_enqueue_scriptsinc\uebns-user.php:31
Maintenance & Trust

About Us Team Maintenance & Trust

Maintenance Signals

WordPress version tested5.3.21
Last updatedFeb 13, 2020
PHP min version5.6
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs60
Developer Profile

About Us Team Developer Profile

Triopsi

7 plugins · 60 total installs

90
trust score
Avg Security Score
94/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect About Us Team

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/about-us-shortcode/assets/css/editor-admin.css/wp-content/plugins/about-us-shortcode/assets/js/logic-form.js/wp-content/plugins/about-us-shortcode/assets/js/images-picker.js/wp-content/plugins/about-us-shortcode/assets/js/uebns-admin-script-color.js/wp-content/plugins/about-us-shortcode/assets/css/front-style.css
Script Paths
https://cdnjs.cloudflare.com/ajax/libs/font-awesome/5.11.2/css/all.css
Version Parameters
about-us-shortcode/assets/css/editor-admin.css?ver=about-us-shortcode/assets/js/logic-form.js?ver=about-us-shortcode/assets/js/images-picker.js?ver=about-us-shortcode/assets/js/uebns-admin-script-color.js?ver=about-us-shortcode/assets/css/front-style.css?ver=

HTML / DOM Fingerprints

CSS Classes
uebns-team-memberuebns-team-member-imageuebns-team-member-nameuebns-team-member-positionuebns-team-member-descriptionuebns-team-member-social-linksuebns-team-member-social-link
Data Attributes
data-uebns-member-id
JS Globals
uebnsobjjs
Shortcode Output
[about_us_shortcode]
FAQ

Frequently Asked Questions about About Us Team