scifi Task Manager Security & Risk Analysis

wordpress.org/plugins/scifi-task-manager

scifi Task Manager is simple admin dash only task manager. Purpose of it is to manage and

20 active installs v0.8.4 PHP + WP 3.7+ Updated Unknown
issue-trackingissuesproject-managerproject-planningtasks
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is scifi Task Manager Safe to Use in 2026?

Generally Safe

Score 100/100

scifi Task Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The 'scifi-task-manager' plugin v0.8.4 exhibits a generally positive security posture based on the provided static analysis. The absence of any detected AJAX handlers, REST API routes, shortcodes, or cron events without proper authentication checks is a significant strength, minimizing the potential attack surface. Furthermore, the code demonstrates good practices by utilizing prepared statements for all SQL queries and avoiding file operations and external HTTP requests, which are common sources of vulnerabilities. The low number of taint flows analyzed (2) with no unsanitized paths or critical/high severity issues is also reassuring.

However, a notable concern lies in the output escaping. With 96 total outputs and only 59% properly escaped, there's a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. This means that nearly half of the plugin's output could potentially be manipulated by attackers to inject malicious scripts, impacting users' browsers. The limited number of nonce and capability checks (2 and 0 respectively) also suggest a potential for privilege escalation or unauthorized actions if certain entry points were to be discovered or introduced in the future.

The plugin's vulnerability history is entirely clean, with no recorded CVEs. This indicates a strong track record of security or a lack of significant public exposure and testing that might reveal latent vulnerabilities. In conclusion, while the plugin has a well-defined and protected attack surface and employs good practices for data handling, the significant proportion of unescaped output presents a clear and present danger that should be addressed urgently. The limited use of capability checks is also a minor concern.

Key Concerns

  • Significant percentage of unescaped output
  • Limited capability checks
Vulnerabilities
None known

scifi Task Manager Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

scifi Task Manager Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
39
57 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared4 total queries

Output Escaping

59% escaped96 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
_scifi_task_manager_admin_settings (scifi-task-manager-helpers.php:644)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

scifi Task Manager Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 29
actionadmin_footerscifi-task-manager-helpers.php:529
actionplugins_loadedscifi-task-manager.php:18
actionadmin_initscifi-task-manager.php:37
actionwp_before_admin_bar_renderscifi-task-manager.php:108
actionadmin_menuscifi-task-manager.php:125
actionwp_dashboard_setupscifi-task-manager.php:148
actionadmin_headscifi-task-manager.php:157
filterpost_type_linkscifi-task-manager.php:162
filterwp_insert_post_datascifi-task-manager.php:172
actionpost_updatedscifi-task-manager.php:179
actionwp_insert_postscifi-task-manager.php:186
actionwp_insert_commentscifi-task-manager.php:195
actionpersonal_optionsscifi-task-manager.php:202
actionedit_user_profile_updatescifi-task-manager.php:217
actionadd_meta_boxes_scifi-task-managerscifi-task-manager.php:225
actionadd_meta_boxes_scifi-task-managerscifi-task-manager.php:238
actionedit_form_after_titlescifi-task-manager.php:332
filterpost_classscifi-task-manager.php:388
actionsave_post_scifi-task-managerscifi-task-manager.php:402
filtercomment_row_actionsscifi-task-manager.php:427
filterbulk_actions-scifi-task-managerscifi-task-manager.php:441
filterbulk_actions-edit-scifi-task-managerscifi-task-manager.php:442
filterpage_row_actionsscifi-task-manager.php:448
filtermanage_edit-scifi-task-manager_columnsscifi-task-manager.php:460
filtermanage_edit-scifi-task-manager_sortable_columnsscifi-task-manager.php:481
actionmanage_scifi-task-manager_posts_custom_columnscifi-task-manager.php:494
filterviews_edit-scifi-task-managerscifi-task-manager.php:503
actionrestrict_manage_postsscifi-task-manager.php:560
filterparse_queryscifi-task-manager.php:587
Maintenance & Trust

scifi Task Manager Maintenance & Trust

Maintenance Signals

WordPress version tested4.3.34
Last updatedUnknown
PHP min version
Downloads3K

Community Trust

Rating94/100
Number of ratings7
Active installs20
Developer Profile

scifi Task Manager Developer Profile

dimitrov.adrian

5 plugins · 200 total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect scifi Task Manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/scifi-task-manager/scifi-task-manager.css/wp-content/plugins/scifi-task-manager/scifi-task-manager.js
Script Paths
/wp-content/plugins/scifi-task-manager/scifi-task-manager.js
Version Parameters
scifi-task-manager/scifi-task-manager.css?ver=scifi-task-manager/scifi-task-manager.js?ver=

HTML / DOM Fingerprints

CSS Classes
scifi-task-manager-widget
HTML Comments
<!-- @menu_position --><!-- @single -->
Data Attributes
data-scifi-task-manager-settings
JS Globals
scifi_task_manager_settings
FAQ

Frequently Asked Questions about scifi Task Manager