
Tasks Planner By ConicPlex Security & Risk Analysis
wordpress.org/plugins/tasks-planner-by-conicplexTasks Planner by Conicplex helps admins efficiently assign tasks to editors, authors, contributors, and other team members.
Is Tasks Planner By ConicPlex Safe to Use in 2026?
Generally Safe
Score 92/100Tasks Planner By ConicPlex has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "tasks-planner-by-conicplex" plugin v1.0.0 presents a mixed security posture. On the positive side, the plugin demonstrates good practices by exclusively using prepared statements for SQL queries and ensuring a high percentage (89%) of output is properly escaped. Furthermore, there is no historical record of vulnerabilities (CVEs), suggesting a potentially robust development process or a lack of prior extensive security auditing. The absence of taint analysis findings indicating unsanitized paths or critical/high severity flows is also encouraging.
However, a significant concern arises from the attack surface analysis, which reveals 4 AJAX handlers, all of which lack authentication checks. This creates a substantial risk, as any unauthenticated user could potentially interact with these AJAX endpoints, leading to unintended consequences or exploitation if the functionality is sensitive. The limited number of capability checks (2) further exacerbates this risk, as it implies these unprotected AJAX endpoints might not adequately restrict access based on user roles.
In conclusion, while the plugin shows strengths in data handling and output escaping, the completely unprotected AJAX endpoints represent a critical weakness. This oversight dramatically increases the potential for exploits, especially in a multi-user WordPress environment. The lack of past vulnerabilities is positive, but it doesn't mitigate the immediate risk posed by the identified architectural flaw in its AJAX endpoints.
Key Concerns
- AJAX handlers without auth checks
- Limited capability checks
- High percentage of properly escaped output
- SQL queries use prepared statements
- No recorded CVEs
- No taint analysis findings
Tasks Planner By ConicPlex Security Vulnerabilities
Tasks Planner By ConicPlex Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Tasks Planner By ConicPlex Attack Surface
AJAX Handlers 4
WordPress Hooks 7
Maintenance & Trust
Tasks Planner By ConicPlex Maintenance & Trust
Maintenance Signals
Community Trust
Tasks Planner By ConicPlex Alternatives
Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker
wedevs-project-manager
Ease Project Management and Task Management using a powerful project manager with Kanban board, Gantt chart, milestone tracking & project reporting.
FluentBoards – Project Management, Task Management, Goal Tracking, Kanban Board, and, Team Collaboration
fluent-boards
The Simplest Project & Task Management Plugin Specifically Crafted for Agencies, Freelancers & Founders.
Taskbuilder – Project Management & Task Management Tool With Kanban Board
taskbuilder
Taskbuilder is a project management and task management plugin for WordPress with Kanban-style boards to organize and track work.
LazyTasks – Project & Task Management with Collaboration, Kanban and Gantt Chart
lazytasks-project-task-management
Comprehensive Task Management, FREE! Minimalist design with powerful features to boost your productivity.
Easy Project
iprojectweb
Easy to use yet powerful project management tool
Tasks Planner By ConicPlex Developer Profile
4 plugins · 10 total installs
How We Detect Tasks Planner By ConicPlex
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tasks-planner-by-conicplex/admin/css/tpcp-admin.css/wp-content/plugins/tasks-planner-by-conicplex/admin/js/tpcp-admin.js/wp-content/plugins/tasks-planner-by-conicplex/asset/tpcp-logo.png/wp-content/plugins/tasks-planner-by-conicplex/admin/js/tpcp-admin.jstasks-planner-by-conicplex/admin/css/tpcp-admin.css?ver=tasks-planner-by-conicplex/admin/js/tpcp-admin.js?ver=HTML / DOM Fingerprints
tpcp-add-new-task-btntpcp-tasks-containertpcp-taskstpcp-tasks-list-containertpcp-tasks-headertpcp-header-itemstpcp-logo-containertpcp-logo+7 more<!-- Page title & Add New Button --><!-- Success Notice --><!-- Error Notice --><!-- Tasks container -->+4 moredata-modaldata-tpcp-tasks-filter-bytpcp_add_new_task_modal_idtpcp_task_add_new_nonce_actiontpcp_tasks_nonce_actiontpcp_assign_user_nonce_actiontpcp_tasks_filter_nonce_action