TaskBreaker – Group Project Management Security & Risk Analysis

wordpress.org/plugins/taskbreaker-project-management

A simple WordPress plugin for managing projects and tasks. Integrated into BuddyPress Groups for best collaborative experience.

200 active installs v1.5.1 PHP + WP 4.2.0+ Updated Aug 10, 2018
collaborationprojectproject-managementtasktask-discussion
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is TaskBreaker – Group Project Management Safe to Use in 2026?

Generally Safe

Score 85/100

TaskBreaker – Group Project Management has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The 'taskbreaker-project-management' plugin v1.5.1 exhibits a generally strong security posture based on the provided static analysis. The plugin demonstrates good development practices with a high percentage of SQL queries using prepared statements and a substantial majority of outputs being properly escaped. The presence of capability checks and a nonce check on its single AJAX handler further indicates an effort to secure its entry points. Notably, there are no recorded vulnerabilities (CVEs) for this plugin, suggesting a history of stable and secure development.

However, a closer examination reveals a few areas that warrant attention. While the attack surface is small, the absence of explicit authentication checks on the single AJAX handler, even if it's not directly exposed to external attacks, is a potential concern. The 2% of SQL queries that do not use prepared statements, while small, represent a potential risk if they involve user-supplied data. Similarly, the 18% of unescaped output, though seemingly minor, could lead to cross-site scripting (XSS) vulnerabilities if these outputs contain or process user-controlled data.

Overall, the plugin appears to be well-maintained and secure, with a commendable lack of historical vulnerabilities. The strengths lie in its robust SQL practices and output escaping. The weaknesses are minor but present, primarily concerning the lack of explicit authorization on the AJAX handler and the small percentages of unescaped output and non-prepared SQL queries. These are minor points that could be improved to further harden the plugin's security.

Key Concerns

  • AJAX handler without explicit auth check
  • SQL queries not using prepared statements (2%)
  • Output not properly escaped (18%)
Vulnerabilities
None known

TaskBreaker – Group Project Management Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

TaskBreaker – Group Project Management Release Timeline

v1.5.1Current
v1.5.0
v1.4.13
v1.4.12
v1.4.11
v1.4.10
v1.4.9
v1.4.8
v1.4.7
v1.4.6
v1.4.5
Code Analysis
Analyzed Mar 16, 2026

TaskBreaker – Group Project Management Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
48 prepared
Unescaped Output
62
282 escaped
Nonce Checks
1
Capability Checks
15
File Operations
1
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

98% prepared49 total queries

Output Escaping

82% escaped344 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

1 flows
<add-ticket> (transactions\routes\add-ticket.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

TaskBreaker – Group Project Management Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_task_breaker_transactions_requesttransactions\controller.php:33
WordPress Hooks 34
actionbefore_delete_postactions\actions.php:12
actionwp_enqueue_scriptscore\enqueue.php:36
actionwp_footercore\enqueue.php:37
filterupload_dircore\file-attachments.php:41
actionbp_core_install_emailsemails\class-buddypress-mail-register.php:18
actionbp_core_install_emailsemails\class-buddypress-mail-register.php:21
actiontb_new_taskemails\class-buddypress-mail-register.php:24
actiontb_new_task_commentemails\class-buddypress-mail-register.php:27
actionbp_notification_settingsemails\class-buddypress-mail-register.php:30
filterbp_notifications_get_registered_componentsincludes\project-notifications.php:27
filterbp_notifications_get_notifications_for_userincludes\project-notifications.php:28
filtertask_breaker_new_taskincludes\project-notifications.php:29
actioninitincludes\project-post-type.php:31
actionwpincludes\project-post-type.php:33
actionwp_enqueue_scriptsincludes\project-post-type.php:36
filterthe_contentincludes\project-post-type.php:100
filterbp_located_templateincludes\project-screens.php:31
filterbp_get_template_stackincludes\project-screens.php:32
actionbp_screensincludes\project-screens.php:33
actionbp_template_titleincludes\project-screens.php:175
actionbp_template_contentincludes\project-screens.php:177
actionbp_template_titleincludes\project-screens.php:192
actionbp_template_contentincludes\project-screens.php:194
actionbp_setup_theme_compatincludes\project-theme-compat.php:12
actionbp_template_include_reset_dummy_post_dataincludes\project-theme-compat.php:23
filterbp_replace_the_contentincludes\project-theme-compat.php:26
actionplugins_loadedtask-breaker.php:42
actioninittask-breaker.php:45
actionbp_loadedtask-breaker.php:48
actionbp_loadedtask-breaker.php:51
actionbp_loadedtask-breaker.php:54
actionadmin_noticestask-breaker.php:60
actionadmin_noticestask-breaker.php:72
actionwidgets_initwidgets\widgets.php:135
Maintenance & Trust

TaskBreaker – Group Project Management Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedAug 10, 2018
PHP min version
Downloads32K

Community Trust

Rating94/100
Number of ratings6
Active installs200
Developer Profile

TaskBreaker – Group Project Management Developer Profile

Joseph G.

6 plugins · 5K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect TaskBreaker – Group Project Management

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about TaskBreaker – Group Project Management