
Custom Team Manager Security & Risk Analysis
wordpress.org/plugins/custom-team-managerThis plugin will display team members using shortcode on your page. You just need to post members details same way as you add a new post.
Is Custom Team Manager Safe to Use in 2026?
Use With Caution
Score 63/100Custom Team Manager has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "custom-team-manager" v2.4.2 plugin exhibits a mixed security posture. While it shows good practices like using prepared statements for all SQL queries and having a reasonable number of capability checks, there are significant concerns. The presence of an unprotected AJAX handler represents a critical entry point that could be exploited without authentication. Furthermore, the output escaping is only at 40%, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities where user-supplied data might not be properly sanitized before being displayed to other users. The plugin's vulnerability history, with one unpatched medium severity CVE for XSS, reinforces these concerns and suggests a pattern of security weaknesses.
While the absence of dangerous functions, file operations, and external HTTP requests is positive, the critical unsecured AJAX endpoint and the low output escaping rate are major red flags. The existence of an unpatched medium severity XSS vulnerability in its history, coupled with the code analysis revealing poor output escaping, strongly suggests that a similar vulnerability could still be present or easily introduced. The plugin has a relatively small attack surface, but the lack of security around one of its entry points significantly elevates the risk. A cautious approach is recommended, prioritizing updates and careful monitoring for further issues.
Key Concerns
- Unprotected AJAX handler
- Low output escaping rate (40%)
- Unpatched medium severity CVE
Custom Team Manager Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Custom Team Manager <= 2.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Custom Team Manager Code Analysis
Output Escaping
Custom Team Manager Attack Surface
AJAX Handlers 1
Shortcodes 3
WordPress Hooks 21
Maintenance & Trust
Custom Team Manager Maintenance & Trust
Maintenance Signals
Community Trust
Custom Team Manager Alternatives
Awesome Team Showcase
awesome-team-showcase
This plugin provides to show awesome team showcase to you post or pages just using shortcode.
WP Roster
wp-roster
WP Roster is a robust roster system for WordPress
BuddyClients Lite
buddyclients-lite
BuddyClients is a flexible and comprehensive platform for any service-based business. This free version includes core functionality.
Oikko – All-in-One Team Management
oikko-team-management
Manage your team with chat, time tracking, HR tools, documents, and more.
Tasks Planner By ConicPlex
tasks-planner-by-conicplex
Tasks Planner by Conicplex helps admins efficiently assign tasks to editors, authors, contributors, and other team members.
Custom Team Manager Developer Profile
1 plugin · 100 total installs
How We Detect Custom Team Manager
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-team-manager/css/stylesheet.css/wp-content/plugins/custom-team-manager/css/admin-style.css/wp-content/plugins/custom-team-manager/js/cmt-options.js/wp-content/plugins/custom-team-manager/js/cmt-options.jscustom-team-manager/css/stylesheet.css?ver=custom-team-manager/css/admin-style.css?ver=custom-team-manager/js/cmt-options.js?ver=HTML / DOM Fingerprints
cmt-linksname="cmt_mem_per_page"name="cmt_ajax_load"name="cmt_custom_css"name="cmt_single_page"name="cmt_profile_page"name="cmt_show_gridview"+1 more[team-members][team-members-profile]