
LazyTasks – Project & Task Management with Collaboration, Kanban and Gantt Chart Security & Risk Analysis
wordpress.org/plugins/lazytasks-project-task-managementComprehensive Task Management, FREE! Minimalist design with powerful features to boost your productivity.
Is LazyTasks – Project & Task Management with Collaboration, Kanban and Gantt Chart Safe to Use in 2026?
High Risk
Score 40/100LazyTasks – Project & Task Management with Collaboration, Kanban and Gantt Chart carries significant security risk with 2 known CVEs, 2 still unpatched. Consider switching to a maintained alternative.
The lazytasks-project-task-management plugin exhibits a significant security risk due to multiple unprotected entry points, particularly its AJAX handlers and REST API routes which lack proper authorization checks. While the plugin demonstrates strong practices in SQL query preparation and output escaping, the presence of unprotected AJAX endpoints and a REST API route significantly broadens its attack surface, making it vulnerable to unauthorized actions. The plugin's vulnerability history is a major concern, with two known critical CVEs, both currently unpatched. These historical vulnerabilities, specifically Incorrect Privilege Assignment and Missing Authorization, directly correlate with the observed lack of authorization checks in the static analysis. This pattern suggests a recurring weakness in how the plugin handles user permissions and access control. While the plugin's adherence to prepared statements and output escaping is commendable, the critical unpatched vulnerabilities and unprotected entry points create a high-risk environment. Prompt patching of existing vulnerabilities and immediate implementation of authorization checks on all entry points are strongly recommended.
Key Concerns
- Unprotected AJAX handlers
- Unprotected REST API routes
- 2 unpatched critical CVEs
- Missing authorization on 2 entry points
LazyTasks – Project & Task Management with Collaboration, Kanban and Gantt Chart Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
LazyTasks <= 1.4.01 - Unauthenticated Privilege Escalation
LazyTasks – Project & Task Management with Collaboration, Kanban and Gantt Chart <= 1.2.29 - Missing Authorization to Uanuthenticated Privilege Escalation
LazyTasks – Project & Task Management with Collaboration, Kanban and Gantt Chart Code Analysis
SQL Query Safety
Output Escaping
LazyTasks – Project & Task Management with Collaboration, Kanban and Gantt Chart Attack Surface
AJAX Handlers 2
REST API Routes 1
WordPress Hooks 26
Maintenance & Trust
LazyTasks – Project & Task Management with Collaboration, Kanban and Gantt Chart Maintenance & Trust
Maintenance Signals
Community Trust
LazyTasks – Project & Task Management with Collaboration, Kanban and Gantt Chart Alternatives
Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker
wedevs-project-manager
Ease Project Management and Task Management using a powerful project manager with Kanban board, Gantt chart, milestone tracking & project reporting.
FluentBoards – Project Management, Task Management, Goal Tracking, Kanban Board, and, Team Collaboration
fluent-boards
The Simplest Project & Task Management Plugin Specifically Crafted for Agencies, Freelancers & Founders.
GemBoards – Project Management, Task Management, Sprint Planning, Team Collaboration, and Kanban board Plugin
gemboards
GemBoards is a project and task management plugin that helps teams manage projects, Kanban boards, and sprint workflows from one place.
Taskbuilder – Project Management & Task Management Tool With Kanban Board
taskbuilder
Taskbuilder is a project management and task management plugin for WordPress with Kanban-style boards to organize and track work.
BuddyTask
buddytask
Adds KanBan like task management boards to Posts, Pages and BuddyPress Groups!
LazyTasks – Project & Task Management with Collaboration, Kanban and Gantt Chart Developer Profile
1 plugin · 70 total installs
How We Detect LazyTasks – Project & Task Management with Collaboration, Kanban and Gantt Chart
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lazytasks-project-task-management/admin/css/pms-rbs-admin.css/wp-content/plugins/lazytasks-project-task-management/admin/frontend/build/index.css/wp-content/plugins/lazytasks-project-task-management/admin/frontend/build/index.js/wp-content/plugins/lazytasks-project-task-management/admin/frontend/build/index.jslazytasks-project-task-management/admin/css/pms-rbs-admin.css?ver=lazytasks-project-task-management/admin/frontend/build/index.css?ver=lazytasks-project-task-management/admin/frontend/build/index.js?ver=HTML / DOM Fingerprints
lazytasks-pagedata-ltask-idlazytask_localize/wp-json/lazytask/v1/