MW Team Gallery Security & Risk Analysis

wordpress.org/plugins/mw-team-gallery

Easly Team Profile Gallery

0 active installs v1.0 PHP + WP 3.6+ Updated Sep 21, 2019
meet-the-teammw-team-galleryteam-galleryteam-memberwp-team
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is MW Team Gallery Safe to Use in 2026?

Generally Safe

Score 85/100

MW Team Gallery has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The 'mw-team-gallery' v1.0 plugin exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, SQL queries, file operations, and external HTTP requests is a strong positive sign. Furthermore, the presence of nonce and capability checks, along with the reliance on prepared statements for SQL, indicates a deliberate effort to implement common WordPress security best practices. The plugin also has a clean vulnerability history, with no known CVEs, which suggests a track record of stable and secure development.

However, a significant concern is the low percentage of properly escaped output. With 27 total outputs and only 26% properly escaped, this leaves a substantial portion vulnerable to cross-site scripting (XSS) attacks. If any of these unescaped outputs contain user-supplied or dynamic data, an attacker could potentially inject malicious scripts. While the attack surface is small and currently appears to have no direct vulnerabilities in AJAX or REST API routes, the insufficient output escaping presents a notable weakness that could be exploited.

In conclusion, 'mw-team-gallery' v1.0 has several strengths, including a minimal attack surface and good SQL handling. Its lack of historical vulnerabilities is also reassuring. The primary and most pressing weakness lies in its inadequate output escaping, which needs immediate attention to mitigate XSS risks. Addressing this would significantly bolster the plugin's overall security.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

MW Team Gallery Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

MW Team Gallery Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
20
7 escaped
Nonce Checks
2
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

26% escaped27 total outputs
Attack Surface

MW Team Gallery Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[mw_team_gallery] mw-team-gallery.php:123
WordPress Hooks 7
actionadd_meta_boxesmw-team-gallery.php:96
actionsave_postmw-team-gallery.php:116
actioninitmw-team-gallery.php:118
actionadd_meta_boxesmw-team-gallery.php:438
actionsave_postmw-team-gallery.php:439
actionadmin_initmw-team-gallery.php:443
actionadmin_menumw-team-gallery.php:453
Maintenance & Trust

MW Team Gallery Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedSep 21, 2019
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

MW Team Gallery Developer Profile

ManiWebify creative web & App agency

2 plugins · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect MW Team Gallery

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mw-team-gallery/style.css

HTML / DOM Fingerprints

CSS Classes
ec-team-membersec-team-singleec-topec-imgec-img2ec-team-titleec-team-desec-bottom+1 more
Data Attributes
id="ec-team-bar"
Shortcode Output
<div class="ec-team-members row" id="ec-team-bar">
FAQ

Frequently Asked Questions about MW Team Gallery