
WP Team – WordPress Team Member Plugin Security & Risk Analysis
wordpress.org/plugins/ht-team-memberThe WP Team Member is a elementor addons, visual composer addons, WordPress Default widgets and Ready Shortcode for WordPress.
Is WP Team – WordPress Team Member Plugin Safe to Use in 2026?
Generally Safe
Score 98/100WP Team – WordPress Team Member Plugin has a strong security track record. Known vulnerabilities have been patched promptly.
The "ht-team-member" plugin version 1.1.8 presents a mixed security posture. While it demonstrates good practices such as 100% usage of prepared statements for SQL queries, a single nonce check, and two capability checks, there are significant areas of concern. The static analysis reveals the presence of a dangerous function, `create_function`, and a concerningly low percentage of properly escaped outputs (55%), suggesting potential for Cross-Site Scripting (XSS) vulnerabilities.
The vulnerability history further amplifies these concerns. The plugin has a history of two medium-severity CVEs, both related to Cross-Site Scripting. While currently unpatched vulnerabilities are zero, the recurring nature of XSS issues is a red flag. The lack of taint analysis data might indicate limited testing or complex code paths that are difficult to analyze automatically, but it doesn't negate the risks identified by other metrics.
Overall, while the plugin has some strong security foundations, the use of dangerous functions, insufficient output escaping, and past XSS vulnerabilities necessitate caution. The potential for XSS attacks, especially given the history, is the most prominent risk. A thorough manual code review is recommended to identify and remediate potential XSS vectors that may not have been caught by the static analysis.
Key Concerns
- Presence of dangerous function create_function
- Low percentage of properly escaped outputs
- History of 2 medium severity CVEs (XSS)
WP Team – WordPress Team Member Plugin Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
HT Team Member <= 1.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
HT Team Member <= 1.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via htteamember Shortcode
WP Team – WordPress Team Member Plugin Code Analysis
Dangerous Functions Found
Output Escaping
WP Team – WordPress Team Member Plugin Attack Surface
Shortcodes 1
WordPress Hooks 18
Maintenance & Trust
WP Team – WordPress Team Member Plugin Maintenance & Trust
Maintenance Signals
Community Trust
WP Team – WordPress Team Member Plugin Alternatives
SwiftAddons for Elementor
swiftaddons-for-elementor
Lightweight Elementor addon pack with Info Box, Team Member, and Testimonial widgets.
Our Team Widget for Elementor
our-team-widget-for-elementor
Our Team Widget for Elementor helps you showcase team member detail in a unique style.
Team Members for Elementor Page Builder
team-members-for-elementor
Team members is an addon for Elementor page builder. Using the extension you can show team members of your organization or an agency in a multi-column …
Unicon extensions
unicon-extensions
support for special content types in your website, such as a service Block, client, and team member.
Promote extensions
promote-extensions
support for special content types in your website, such as a service Block, client, and team member,counter.
WP Team – WordPress Team Member Plugin Developer Profile
23 plugins · 64K total installs
How We Detect WP Team – WordPress Team Member Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ht-team-member/assests/css/ht-teammember.css/wp-content/plugins/ht-team-member/assests/css/font-awesome.min.css/wp-content/plugins/ht-team-member/assests/css/slick.min.css/wp-content/plugins/ht-team-member/assests/js/slick.min.js/wp-content/plugins/ht-team-member/assests/js/ht-teammin.js/wp-content/plugins/ht-team-member/admin/assets/css/admin_optionspanel.css/wp-content/plugins/ht-team-member/assests/js/slick.min.js/wp-content/plugins/ht-team-member/assests/js/ht-teammin.jsht-team-member/assests/css/ht-teammember.css?ver=ht-team-member/assests/css/font-awesome.min.css?ver=ht-team-member/assests/css/slick.min.css?ver=ht-team-member/assests/js/slick.min.js?ver=ht-team-member/assests/js/ht-teammin.js?ver=ht-team-member/admin/assets/css/admin_optionspanel.css?ver=HTML / DOM Fingerprints
ht-team-member-wrapdata-member-idhtteammember_admin_url[ht_team_member id=[ht_team_member]