
Table Manager Security & Risk Analysis
wordpress.org/plugins/table-managerTable Manager plugin helps to create table from wordpress posts, page.
Is Table Manager Safe to Use in 2026?
Mostly Safe
Score 78/100Table Manager is generally safe to use. 1 past CVE were resolved.
The "table-manager" plugin version 1.0.0 demonstrates a strong security posture based on the provided static analysis. The plugin successfully implements proper output escaping for all identified outputs and utilizes prepared statements for a majority of its SQL queries, indicating good development practices. Furthermore, the absence of dangerous functions, file operations, and external HTTP requests is a positive sign for its security. The plugin also includes nonce checks, which are crucial for preventing certain types of attacks. The vulnerability history is currently clean, with no recorded CVEs, suggesting a responsible approach to security by the developers or a lack of previously discovered vulnerabilities.
Despite these strengths, there are areas for improvement. The lack of capability checks on any of the identified entry points (shortcodes) is a significant concern. This means that any user, regardless of their role or permissions, could potentially interact with these shortcodes, opening the door for unauthorized actions or information disclosure. While taint analysis found no critical or high severity flows, the presence of two flows warrants attention, even if they are currently sanitized. The relatively small number of SQL queries and the absence of any unpatched vulnerabilities are positive but do not fully mitigate the risk posed by the missing capability checks.
In conclusion, "table-manager" v1.0.0 has a good foundation of secure coding practices, particularly in output escaping and SQL query sanitization. However, the critical oversight of not implementing capability checks on its shortcode entry points represents a substantial security weakness that could be exploited. The absence of past vulnerabilities is encouraging, but it does not negate the immediate risk associated with the current implementation.
Key Concerns
- Missing capability checks on shortcodes
Table Manager Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Table Manager <= 1.0.0 - Authenticated (Contributor+) Sensitive Information Exposure via 'table' Shortcode Attribute
Table Manager Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Table Manager Attack Surface
Shortcodes 2
WordPress Hooks 5
Maintenance & Trust
Table Manager Maintenance & Trust
Maintenance Signals
Community Trust
Table Manager Alternatives
CustomTables – Create, Read, Update, and Delete
customtables
The Custom Tables plugin allows you to create and manage custom database tables, display catalogs, forms, and tables using Twig templating language.
FortressDB
fortressdb
High-speed, secure database plugin for WordPress form data
My Tables
my-tables
Displays table information of your WordPress Database.
CSVMapper
csvmapper
Feed data from CSV files to the WordPress database. Create posts or add post meta, user meta or even add data to custom tables.
TablePress – Tables in WordPress made easy
tablepress
Embed beautiful, accessible, and interactive tables into your WordPress website’s posts and pages, without having to write code!
Table Manager Developer Profile
3 plugins · 10 total installs
How We Detect Table Manager
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/table-manager/css/admin.css/wp-content/plugins/table-manager/js/admin.js/wp-content/plugins/table-manager/js/admin.jstable-manager/css/admin.css?ver=table-manager/js/admin.js?ver=HTML / DOM Fingerprints
tm-formfull-width-inputtablemanager-listname="table_name"name="create_table"name="delete_table"name="delete_table_submit"name="delete_column"name="remove_column_nonce"+1 more[table_manager table='<code>[table_manager table='