People profiles, team- and company pages Security & Risk Analysis

wordpress.org/plugins/company-presentation

A professional profile section with an 'About Us' Page with visual Network, Team and People profiles.

20 active installs v5.1.0 PHP + WP 4.0+ Updated Feb 18, 2019
employee-advocayemployee-directoryemployee-listemployee-profilepeople
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is People profiles, team- and company pages Safe to Use in 2026?

Generally Safe

Score 85/100

People profiles, team- and company pages has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "company-presentation" plugin v5.1.0 exhibits a mixed security posture. On the positive side, it boasts a clean vulnerability history with no recorded CVEs, suggesting a generally stable and well-maintained codebase. The absence of dangerous functions, file operations, and the use of prepared statements for all SQL queries are excellent security practices. Furthermore, all identified entry points appear to have some form of authorization, indicated by the presence of a nonce check and no unprotected entry points. However, significant concerns arise from the static code analysis. A critical finding is that 100% of the identified output points are not properly escaped, creating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The presence of unsanitized paths in taint analysis also points to potential vulnerabilities, although their severity is not explicitly stated as critical or high in the provided data. The plugin also makes external HTTP requests, which, while not inherently insecure, can be a vector for vulnerabilities if not handled carefully. The lack of capability checks for its entry points, despite the presence of a nonce, is another area of potential weakness. While the plugin has no known vulnerabilities, the unescaped output and potential taint flow issues present immediate risks that need to be addressed to improve its overall security.

Key Concerns

  • All output is unescaped
  • Flows with unsanitized paths
  • No capability checks on entry points
Vulnerabilities
None known

People profiles, team- and company pages Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

People profiles, team- and company pages Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
12
0 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

0% escaped12 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<careerpagespluginhandler> (php\careerpagespluginhandler.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

People profiles, team- and company pages Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 1

authwp_ajax_prodii_shortcode_contentcareerpagesplugin.php:803

Shortcodes 1

[careerpages] careerpagesplugin.php:471
WordPress Hooks 5
filterthe_postscareerpagesplugin.php:469
actionwp_enqueue_scriptscareerpagesplugin.php:470
actionadmin_menucareerpagesplugin.php:800
actionadmin_initcareerpagesplugin.php:801
actionadmin_enqueue_scriptscareerpagesplugin.php:802
Maintenance & Trust

People profiles, team- and company pages Maintenance & Trust

Maintenance Signals

WordPress version tested5.0.25
Last updatedFeb 18, 2019
PHP min version
Downloads15K

Community Trust

Rating86/100
Number of ratings3
Active installs20
Developer Profile

People profiles, team- and company pages Developer Profile

Ralph Rezende Larsen

1 plugin · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect People profiles, team- and company pages

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/company-presentation/css/common.css/wp-content/plugins/company-presentation/css/template.css/wp-content/plugins/company-presentation/css/magnific-popup.css/wp-content/plugins/company-presentation/js/company-presentation.js/wp-content/plugins/company-presentation/js/magnific-popup.js/wp-content/plugins/company-presentation/js/swiper.min.js
Script Paths
/wp-content/plugins/company-presentation/js/company-presentation.js/wp-content/plugins/company-presentation/js/magnific-popup.js/wp-content/plugins/company-presentation/js/swiper.min.js
Version Parameters
company-presentation/css/common.css?ver=company-presentation/css/template.css?ver=company-presentation/css/magnific-popup.css?ver=company-presentation/js/company-presentation.js?ver=company-presentation/js/magnific-popup.js?ver=company-presentation/js/swiper.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
company-presentation-containercp-profile-blockcp-team-blockcp-slider-wrappercp-member-card
Data Attributes
data-company-presentation-id
JS Globals
companyPresentationSettingsCpFrontendMagnificPopup
REST Endpoints
/wp-json/company-presentation/v1/settings
Shortcode Output
[company_presentation id="[team_presentation id="
FAQ

Frequently Asked Questions about People profiles, team- and company pages