
Taskbuilder – Project Management & Task Management Tool With Kanban Board Security & Risk Analysis
wordpress.org/plugins/taskbuilderTaskbuilder is a project management and task management plugin for WordPress with Kanban-style boards to organize and track work.
Is Taskbuilder – Project Management & Task Management Tool With Kanban Board Safe to Use in 2026?
Generally Safe
Score 95/100Taskbuilder – Project Management & Task Management Tool With Kanban Board has a strong security track record. Known vulnerabilities have been patched promptly.
The 'taskbuilder' plugin v5.0.5 exhibits a concerning security posture, primarily due to a massive attack surface composed of 153 unprotected AJAX handlers. This represents a significant risk, as any of these entry points could potentially be exploited without proper authorization checks. While the code demonstrates some good practices, such as the high percentage of prepared SQL statements and properly escaped output, the sheer number of unauthenticated AJAX endpoints overshadows these strengths. The taint analysis reveals 14 high-severity flows with unsanitized paths, directly contributing to the plugin's vulnerability history of missing authorization, SQL injection, and XSS. Although there are currently no unpatched CVEs, the historical prevalence of these common vulnerability types strongly suggests a recurring pattern of insecure input handling and authorization flaws. The presence of the `unserialize` function also poses a risk, especially if user-controlled data is passed to it without proper validation.
Key Concerns
- Large attack surface with unprotected AJAX handlers
- High-severity unsanitized taint flows
- Dangerous function: unserialize
- Bundled outdated library: DataTables v1.10.25
- Bundled outdated library: dompdf
- Bundled outdated library: Select2
- Significant historical CVEs related to common vuln types
Taskbuilder – Project Management & Task Management Tool With Kanban Board Security Vulnerabilities
CVEs by Year
Severity Breakdown
11 total CVEs
Taskbuilder <= 5.0.3 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Block Emails' Field
Taskbuilder <= 5.0.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Project/Task Comment Creation
Taskbuilder <= 5.0.2 - Authenticated (Subscriber+) SQL Injection via 'order' and 'sort_by' Parameters
Taskbuilder <= 4.0.9 - Reflected Cross-Site Scripting
Taskbuilder <= 4.0.7 - Missing Authorization
Taskbuilder <= 4.0.1 - Authenticated (Subscriber+) SQL Injection
Taskbuilder <= 3.0.8 - Authenticated (Admin+) SQL Injection
Taskbuilder <= 3.0.6 - Authenticated (Subscriber+) SQL Injection
Taskbuilder – WordPress Project & Task Management plugin <= 3.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via wppm_tasks Shortcode
Taskbuilder – WordPress Project & Task Management plugin <= 3.0.4 - Authenticated (Admin+) SQL injection
Taskbuilder <= 1.0.7 - Authenticated (Subscriber+) Stored Cross-Site Scripting
Taskbuilder – Project Management & Task Management Tool With Kanban Board Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Taskbuilder – Project Management & Task Management Tool With Kanban Board Attack Surface
AJAX Handlers 153
Shortcodes 3
WordPress Hooks 26
Scheduled Events 3
Maintenance & Trust
Taskbuilder – Project Management & Task Management Tool With Kanban Board Maintenance & Trust
Maintenance Signals
Community Trust
Taskbuilder – Project Management & Task Management Tool With Kanban Board Alternatives
FluentBoards – Project Management, Task Management, Goal Tracking, Kanban Board, and, Team Collaboration
fluent-boards
The Simplest Project & Task Management Plugin Specifically Crafted for Agencies, Freelancers & Founders.
QuickTasker
quicktasker
Task management plugin designed to help you organize your projects, streamline workflows, and get tasks done efficiently.
LatePoint – Calendar Booking Plugin for Appointments and Events
latepoint
Optimize your appointment scheduling with our plugin. Sync calendars, automate reminders, and keep your bookings organized.
Online Scheduling and Appointment Booking System – Bookly
bookly-responsive-appointment-booking-tool
Appointment booking system for WordPress — schedule appointments, manage calendars, send reminders, take payments. Start booking today!
Events Manager – Calendar, Bookings, Tickets, and more!
events-manager
Events calendar with bookings, scheduling, appointments, event registration, tickets, recurring events, and venue management.
Taskbuilder – Project Management & Task Management Tool With Kanban Board Developer Profile
1 plugin · 800 total installs
How We Detect Taskbuilder – Project Management & Task Management Tool With Kanban Board
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/taskbuilder/assets/css/wppm-style.css/wp-content/plugins/taskbuilder/assets/css/wppm-bootstrap.css/wp-content/plugins/taskbuilder/assets/css/wppm-datatables.css/wp-content/plugins/taskbuilder/assets/css/wppm-animate.css/wp-content/plugins/taskbuilder/assets/css/wppm-responsive.css/wp-content/plugins/taskbuilder/assets/js/wppm-bootstrap.js/wp-content/plugins/taskbuilder/assets/js/wppm-functions.js/wp-content/plugins/taskbuilder/assets/js/wppm-moment.js+5 more/wp-content/plugins/taskbuilder/assets/js/wppm-bootstrap.js/wp-content/plugins/taskbuilder/assets/js/wppm-functions.js/wp-content/plugins/taskbuilder/assets/js/wppm-moment.js/wp-content/plugins/taskbuilder/assets/js/wppm-daterangepicker.js/wp-content/plugins/taskbuilder/assets/js/wppm-chart.js/wp-content/plugins/taskbuilder/assets/js/wppm-custom.js+2 moretaskbuilder/assets/css/wppm-style.css?ver=taskbuilder/assets/css/wppm-bootstrap.css?ver=taskbuilder/assets/css/wppm-datatables.css?ver=taskbuilder/assets/css/wppm-animate.css?ver=taskbuilder/assets/css/wppm-responsive.css?ver=taskbuilder/assets/js/wppm-bootstrap.js?ver=taskbuilder/assets/js/wppm-functions.js?ver=taskbuilder/assets/js/wppm-moment.js?ver=taskbuilder/assets/js/wppm-daterangepicker.js?ver=taskbuilder/assets/js/wppm-chart.js?ver=taskbuilder/assets/js/wppm-custom.js?ver=taskbuilder/assets/js/wppm-datatables.js?ver=taskbuilder/assets/js/wppm-select2.js?ver=HTML / DOM Fingerprints
wppm-containerwppm-add-projectwppm-close-projectwppm-btn-closewppm-project-titlewppm-project-descriptionwppm-project-datewppm-project-assigned+20 more<!-- Taskbuilder Admin --><!-- Taskbuilder Frontend -->data-wppm-actiondata-wppm-project-iddata-wppm-task-iddata-wppm-category-iddata-wppm-status-iddata-wppm-priority-id+1 moreWPPM_Adminwppm_varswppm_ajax_url/wp-json/taskbuilder/v1/projects/wp-json/taskbuilder/v1/tasks/wp-json/taskbuilder/v1/users[taskbuilder_projects][taskbuilder_tasks][taskbuilder_dashboard]