
Dear Project Manager Security & Risk Analysis
wordpress.org/plugins/bipo-project-managerA comprehensive project management plugin for WordPress with team collaboration, applications, and submissions.
Is Dear Project Manager Safe to Use in 2026?
Generally Safe
Score 100/100Dear Project Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The bipo-project-manager plugin version 1.0.15 exhibits a generally good security posture, with several strengths evident in its code. The complete absence of dangerous functions, file operations, and external HTTP requests is a positive sign. Furthermore, all SQL queries utilize prepared statements, and there are no recorded vulnerabilities in its history, indicating diligent development practices. The plugin also shows good attention to security by performing nonce and capability checks on a significant number of its internal operations.
However, a notable concern lies within its attack surface. Out of a total of 12 entry points, 5 are unprotected, specifically 5 REST API routes lacking permission callbacks. This presents a significant risk, as these routes can potentially be accessed and manipulated by unauthenticated users, leading to unintended actions or information disclosure. While the taint analysis found no critical or high-severity issues, the presence of unprotected entry points remains a critical area for improvement. The plugin's static analysis shows a high percentage of properly escaped output, but the 16% that is not properly escaped could still pose an XSS risk if that output is derived from user-supplied data.
In conclusion, bipo-project-manager demonstrates good underlying security practices in its core functions and data handling. The lack of historical vulnerabilities is a strong indicator of responsible development. The primary weakness is the exposed REST API endpoints, which require immediate attention to implement proper authorization checks. Addressing this will significantly enhance the plugin's overall security.
Key Concerns
- REST API routes without permission callbacks
- Unescaped output detected
Dear Project Manager Security Vulnerabilities
Dear Project Manager Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Dear Project Manager Attack Surface
AJAX Handlers 6
REST API Routes 5
Shortcodes 1
WordPress Hooks 36
Maintenance & Trust
Dear Project Manager Maintenance & Trust
Maintenance Signals
Community Trust
Dear Project Manager Alternatives
GS Behance Portfolio – Display Projects, Gallery & Slider
gs-behance-portfolio
Showcase Behance projects on your site with GS Behance Portfolio. Display in Grid, Slider, Gallery & more responsive layouts.
Simple Folio
simple-folio
This plugin lets you to create beautiful filterable responsive portfolio.
OpenAsset
openasset
Sync your AEC Project Portfolio, Employees and Images from OpenAsset to your Wordpress Website.
GemBoards – Project Management, Task Management, Sprint Planning, Team Collaboration, and Kanban board Plugin
gemboards
GemBoards is a project and task management plugin that helps teams manage projects, Kanban boards, and sprint workflows from one place.
WPZOOM Portfolio Lite – Filterable Portfolio Plugin
wpzoom-portfolio
Portfolio plugin for WordPress. Create filterable portfolio grids with masonry layouts and lightbox. Ideal for photographers, designers, agencies.
Dear Project Manager Developer Profile
2 plugins · 0 total installs
How We Detect Dear Project Manager
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bipo-project-manager/assets/css/bipo-project-manager-style.css/wp-content/plugins/bipo-project-manager/assets/js/admin.js/wp-content/plugins/bipo-project-manager/assets/js/app.js/wp-content/plugins/bipo-project-manager/assets/js/setup.js/wp-content/plugins/bipo-project-manager/assets/js/admin.js/wp-content/plugins/bipo-project-manager/assets/js/app.js/wp-content/plugins/bipo-project-manager/assets/js/setup.jsbipo-project-manager/assets/css/bipo-project-manager-style.css?ver=bipo-project-manager/assets/js/admin.js?ver=bipo-project-manager/assets/js/app.js?ver=bipo-project-manager/assets/js/setup.js?ver=HTML / DOM Fingerprints
dear-pm-setup-wizard<!-- DEARPM_SETUP_WIZARD_START --><!-- DEARPM_SETUP_WIZARD_END --><!-- DEACTIVATION_MODAL_START --><!-- DEACTIVATION_MODAL_END -->data-dearprma-noncedearprma_ajax_object/wp-json/dearprma/v1/setup/wp-json/dearprma/v1/deactivate