Custom Team Manager Security & Risk Analysis

wordpress.org/plugins/custom-team-manager

This plugin will display team members using shortcode on your page. You just need to post members details same way as you add a new post.

100 active installs v2.4.2 PHP + WP 3.5+ Updated Aug 24, 2022
add-team-membercustom-team-managementcustom-team-managerteam-managementteam-manager
63
C · Use Caution
CVEs total1
Unpatched1
Last CVESep 5, 2025
Safety Verdict

Is Custom Team Manager Safe to Use in 2026?

Use With Caution

Score 63/100

Custom Team Manager has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Sep 5, 2025Updated 3yr ago
Risk Assessment

The "custom-team-manager" v2.4.2 plugin exhibits a mixed security posture. While it shows good practices like using prepared statements for all SQL queries and having a reasonable number of capability checks, there are significant concerns. The presence of an unprotected AJAX handler represents a critical entry point that could be exploited without authentication. Furthermore, the output escaping is only at 40%, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities where user-supplied data might not be properly sanitized before being displayed to other users. The plugin's vulnerability history, with one unpatched medium severity CVE for XSS, reinforces these concerns and suggests a pattern of security weaknesses.

While the absence of dangerous functions, file operations, and external HTTP requests is positive, the critical unsecured AJAX endpoint and the low output escaping rate are major red flags. The existence of an unpatched medium severity XSS vulnerability in its history, coupled with the code analysis revealing poor output escaping, strongly suggests that a similar vulnerability could still be present or easily introduced. The plugin has a relatively small attack surface, but the lack of security around one of its entry points significantly elevates the risk. A cautious approach is recommended, prioritizing updates and careful monitoring for further issues.

Key Concerns

  • Unprotected AJAX handler
  • Low output escaping rate (40%)
  • Unpatched medium severity CVE
Vulnerabilities
1

Custom Team Manager Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-58840medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Custom Team Manager <= 2.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

Sep 5, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Custom Team Manager Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
6 escaped
Nonce Checks
1
Capability Checks
8
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

40% escaped15 total outputs
Attack Surface
1 unprotected

Custom Team Manager Attack Surface

Entry Points4
Unprotected1

AJAX Handlers 1

authwp_ajax_cmt_hide_noticecustom-team-manager.php:126

Shortcodes 3

[team-members] inc\shortcodes.php:163
[team-members-profile] inc\shortcodes.php:269
[cmt-content] inc\shortcodes.php:277
WordPress Hooks 21
actioninitcustom-team-manager.php:18
actionwp_enqueue_scriptscustom-team-manager.php:24
actionadmin_enqueue_scriptscustom-team-manager.php:35
actionadmin_enqueue_scriptscustom-team-manager.php:43
actionadmin_initcustom-team-manager.php:115
actionadmin_noticescustom-team-manager.php:122
actioninitinc\functions.php:46
actionadmin_menuinc\functions.php:50
actionadmin_initinc\functions.php:56
actionadmin_initinc\functions.php:201
actionadd_meta_boxesinc\functions.php:240
actionsave_postinc\functions.php:271
actionadd_meta_boxesinc\functions.php:289
actionsave_postinc\functions.php:308
actionadd_meta_boxesinc\functions.php:328
actionsave_postinc\functions.php:347
actionadd_meta_boxesinc\functions.php:366
actionsave_postinc\functions.php:385
actionwp_headinc\functions.php:433
actioninitinc\shortcodes.php:165
actioninitinc\shortcodes.php:271
Maintenance & Trust

Custom Team Manager Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedAug 24, 2022
PHP min version
Downloads15K

Community Trust

Rating94/100
Number of ratings16
Active installs100
Developer Profile

Custom Team Manager Developer Profile

Ibnul H.

1 plugin · 100 total installs

68
trust score
Avg Security Score
63/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Custom Team Manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/custom-team-manager/css/stylesheet.css/wp-content/plugins/custom-team-manager/css/admin-style.css/wp-content/plugins/custom-team-manager/js/cmt-options.js
Script Paths
/wp-content/plugins/custom-team-manager/js/cmt-options.js
Version Parameters
custom-team-manager/css/stylesheet.css?ver=custom-team-manager/css/admin-style.css?ver=custom-team-manager/js/cmt-options.js?ver=

HTML / DOM Fingerprints

CSS Classes
cmt-links
Data Attributes
name="cmt_mem_per_page"name="cmt_ajax_load"name="cmt_custom_css"name="cmt_single_page"name="cmt_profile_page"name="cmt_show_gridview"+1 more
Shortcode Output
[team-members][team-members-profile]
FAQ

Frequently Asked Questions about Custom Team Manager