Tasks Planner By ConicPlex Security & Risk Analysis

wordpress.org/plugins/tasks-planner-by-conicplex

Tasks Planner by Conicplex helps admins efficiently assign tasks to editors, authors, contributors, and other team members.

0 active installs v1.0.0 PHP 7.0+ WP 5.2+ Updated Jan 2, 2025
project-managementtask-assignmenttask-managementteam-managementto-do-list
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Tasks Planner By ConicPlex Safe to Use in 2026?

Generally Safe

Score 92/100

Tasks Planner By ConicPlex has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "tasks-planner-by-conicplex" plugin v1.0.0 presents a mixed security posture. On the positive side, the plugin demonstrates good practices by exclusively using prepared statements for SQL queries and ensuring a high percentage (89%) of output is properly escaped. Furthermore, there is no historical record of vulnerabilities (CVEs), suggesting a potentially robust development process or a lack of prior extensive security auditing. The absence of taint analysis findings indicating unsanitized paths or critical/high severity flows is also encouraging.

However, a significant concern arises from the attack surface analysis, which reveals 4 AJAX handlers, all of which lack authentication checks. This creates a substantial risk, as any unauthenticated user could potentially interact with these AJAX endpoints, leading to unintended consequences or exploitation if the functionality is sensitive. The limited number of capability checks (2) further exacerbates this risk, as it implies these unprotected AJAX endpoints might not adequately restrict access based on user roles.

In conclusion, while the plugin shows strengths in data handling and output escaping, the completely unprotected AJAX endpoints represent a critical weakness. This oversight dramatically increases the potential for exploits, especially in a multi-user WordPress environment. The lack of past vulnerabilities is positive, but it doesn't mitigate the immediate risk posed by the identified architectural flaw in its AJAX endpoints.

Key Concerns

  • AJAX handlers without auth checks
  • Limited capability checks
  • High percentage of properly escaped output
  • SQL queries use prepared statements
  • No recorded CVEs
  • No taint analysis findings
Vulnerabilities
None known

Tasks Planner By ConicPlex Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Tasks Planner By ConicPlex Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
12
93 escaped
Nonce Checks
5
Capability Checks
2
File Operations
0
External Requests
3
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

89% escaped105 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<tpcp-admin-display> (admin\partials\tpcp-admin-display.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
4 unprotected

Tasks Planner By ConicPlex Attack Surface

Entry Points4
Unprotected4

AJAX Handlers 4

authwp_ajax_tpcp_get_tasksincludes\class-tpcp.php:163
authwp_ajax_tpcp_get_task_detailsincludes\class-tpcp.php:166
authwp_ajax_tpcp_get_usersincludes\class-tpcp.php:169
authwp_ajax_tpcp_add_task_commentincludes\class-tpcp.php:172
WordPress Hooks 7
actionplugins_loadedincludes\class-tpcp.php:135
actionadmin_enqueue_scriptsincludes\class-tpcp.php:150
actionadmin_enqueue_scriptsincludes\class-tpcp.php:151
actionadmin_menuincludes\class-tpcp.php:154
actioninitincludes\class-tpcp.php:157
actioninitincludes\class-tpcp.php:160
actionadmin_noticesincludes\class-tpcp.php:175
Maintenance & Trust

Tasks Planner By ConicPlex Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedJan 2, 2025
PHP min version7.0
Downloads577

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Tasks Planner By ConicPlex Developer Profile

ConicPlex

4 plugins · 10 total installs

93
trust score
Avg Security Score
98/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Tasks Planner By ConicPlex

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tasks-planner-by-conicplex/admin/css/tpcp-admin.css/wp-content/plugins/tasks-planner-by-conicplex/admin/js/tpcp-admin.js/wp-content/plugins/tasks-planner-by-conicplex/asset/tpcp-logo.png
Script Paths
/wp-content/plugins/tasks-planner-by-conicplex/admin/js/tpcp-admin.js
Version Parameters
tasks-planner-by-conicplex/admin/css/tpcp-admin.css?ver=tasks-planner-by-conicplex/admin/js/tpcp-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
tpcp-add-new-task-btntpcp-tasks-containertpcp-taskstpcp-tasks-list-containertpcp-tasks-headertpcp-header-itemstpcp-logo-containertpcp-logo+7 more
HTML Comments
<!-- Page title & Add New Button --><!-- Success Notice --><!-- Error Notice --><!-- Tasks container -->+4 more
Data Attributes
data-modaldata-tpcp-tasks-filter-by
JS Globals
tpcp_add_new_task_modal_idtpcp_task_add_new_nonce_actiontpcp_tasks_nonce_actiontpcp_assign_user_nonce_actiontpcp_tasks_filter_nonce_action
FAQ

Frequently Asked Questions about Tasks Planner By ConicPlex