
Propel Security & Risk Analysis
wordpress.org/plugins/propelThis plugin allows users to manage projects and tasks.
Is Propel Safe to Use in 2026?
Generally Safe
Score 85/100Propel has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "propel" plugin v2.0.4 exhibits a mixed security posture. While it has no recorded vulnerability history and uses prepared statements for the majority of its SQL queries, several concerning patterns emerge from the static analysis. The plugin presents an attack surface with 3 entry points, one of which is an AJAX handler that lacks authentication checks. This is a significant concern as it could allow unauthenticated users to trigger potentially sensitive functionality.
Taint analysis reveals two high-severity flows with unsanitized paths, indicating potential risks of injection or unintended data manipulation if user-supplied data is not properly validated and sanitized before being used. Furthermore, a substantial 91% of output is not properly escaped, posing a risk of Cross-Site Scripting (XSS) vulnerabilities where user-controlled data displayed on the frontend could contain malicious scripts. The bundled DataTables library at v1.7.6 is also outdated, which could be a vector for exploits if vulnerabilities exist in that specific version.
Despite the absence of known CVEs, the identified code-level weaknesses, particularly the unauthenticated AJAX handler, high-severity unsanitized flows, and widespread output unescaping, create significant potential for exploitation. The plugin's strengths lie in its lack of direct file operations or external HTTP requests and its generally good use of prepared statements for SQL. However, the identified issues necessitate immediate attention to mitigate the risks.
Key Concerns
- Unauthenticated AJAX handler found
- High severity taint flows with unsanitized paths (2)
- Large percentage of unescaped output (91%)
- Bundled outdated library: DataTables v1.7.6
Propel Security Vulnerabilities
Propel Release Timeline
Propel Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Propel Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 48
Maintenance & Trust
Propel Maintenance & Trust
Maintenance Signals
Community Trust
Propel Alternatives
TaskBreaker – Group Project Management
taskbreaker-project-management
A simple WordPress plugin for managing projects and tasks. Integrated into BuddyPress Groups for best collaborative experience.
Webvizio
webvizio
The Ultimate Visual Feedback, Collaboration & Productivity Tool for Web Professionals.
PT Project Notebooks
project-notebooks
WordPress event & project management: meeting minutes, track tasks, create budgets, and publish project notebooks to the front-end.
GemBoards – Project Management, Task Management, Sprint Planning, Team Collaboration, and Kanban board Plugin
gemboards
GemBoards is a project and task management plugin that helps teams manage projects, Kanban boards, and sprint workflows from one place.
Easy Project
iprojectweb
Easy to use yet powerful project management tool
Propel Developer Profile
2 plugins · 20 total installs
How We Detect Propel
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/propel/gen/ui.css/wp-content/plugins/propel/style.css/wp-content/plugins/propel/js/jquery.dataTables.min.js/wp-content/plugins/propel/js/functions.js/wp-content/plugins/propel/js/jquery.ui.datepicker.min.js/wp-content/plugins/propel/js/jquery.ui.progressbar.min.jspropel/style.css?ver=propel/gen/ui.css?ver=HTML / DOM Fingerprints
propel-uiid="propel_dnd"id="propel_user_restrictions"id="propel_time_tracking"id="show_start_date"id="show_end_date"id="show_client"