
Eonet Project Manager Security & Risk Analysis
wordpress.org/plugins/eonet-project-managerMake your site a complete project management tool: create projects, set permissions and assign tasks your users.
Is Eonet Project Manager Safe to Use in 2026?
Generally Safe
Score 85/100Eonet Project Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The eonet-project-manager plugin v1.0.5 presents a mixed security posture. On the positive side, it has no recorded vulnerabilities (CVEs) or reported issues, and it utilizes nonce checks and capability checks to some extent. However, the static analysis reveals significant areas of concern. A substantial portion of its attack surface, specifically 10 out of 19 AJAX handlers, lacks authentication checks, leaving them potentially exposed to unauthorized access and execution.
Further concerns arise from the presence of the `unserialize` function, which, without proper sanitization or validation of the data it processes, can lead to deserialization vulnerabilities. The SQL query practices are also questionable, with only 50% using prepared statements, indicating a risk of SQL injection in the remaining queries. The output escaping is also not consistently applied, with over half of the outputs potentially vulnerable to cross-site scripting (XSS).
Despite the lack of historical vulnerabilities, the current code analysis highlights several inherent risks. The large number of unprotected AJAX endpoints, the use of `unserialize`, and the inconsistent output escaping are significant security weaknesses. While the absence of CVEs is a positive indicator, it doesn't negate the potential for exploitation based on the identified code flaws. A cautious approach is warranted due to these specific code-level risks.
Key Concerns
- Unprotected AJAX handlers
- Dangerous function: unserialize
- SQL queries not using prepared statements
- Improper output escaping
- Low number of capability checks
Eonet Project Manager Security Vulnerabilities
Eonet Project Manager Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Eonet Project Manager Attack Surface
AJAX Handlers 19
WordPress Hooks 44
Maintenance & Trust
Eonet Project Manager Maintenance & Trust
Maintenance Signals
Community Trust
Eonet Project Manager Alternatives
Zephyr Project Manager
zephyr-project-manager
Zephyr Project Manager is a modern, easy to use sophisticated project manager for WordPress.
WP To Do
wp-todo
WP-Todo: Smart To-Do List & Task Management Plugin for WordPress
Easy Project
iprojectweb
Easy to use yet powerful project management tool
Desert Companion
desert-companion
Desert Companion Enhances Desert Themes with additional functionality.
WPZOOM Portfolio Lite – Filterable Portfolio Plugin
wpzoom-portfolio
Portfolio plugin for WordPress. Create filterable portfolio grids with masonry layouts and lightbox. Ideal for photographers, designers, agencies.
Eonet Project Manager Developer Profile
4 plugins · 510 total installs
How We Detect Eonet Project Manager
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/eonet-project-manager/core/assets/js/eonet_project_manager.js/wp-content/plugins/eonet-project-manager/core/assets/css/eonet-project-manager-style.min.csseonet-project-manager/assets/js/eonet_project_manager.js?ver=eonet-project-manager/assets/css/eonet-project-manager-style.min.css?ver=HTML / DOM Fingerprints
eonet-project-managereonet_project_managerEONET_PROJECTSeopm_ajax_object