Team Builder Showcase Security & Risk Analysis

wordpress.org/plugins/team-buider-showcase

The top WordPress Team plugin helps you display profiles of your team members in a grid or slider layout easily by using a simple shortcode.

40 active installs v1.0.7 PHP 5.6+ WP 5.2+ Updated Apr 20, 2025
teamteam-builderteam-builder-showcaseteam-members-showcaseteam-showcase
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Team Builder Showcase Safe to Use in 2026?

Generally Safe

Score 100/100

Team Builder Showcase has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The "team-builder-showcase" plugin v1.0.7 demonstrates a generally strong security posture, adhering to several good security practices. The use of prepared statements for all SQL queries and a high percentage of properly escaped output are commendable. The absence of dangerous functions, file operations, and external HTTP requests further reduces the potential attack surface. The plugin also boasts a significant number of nonce and capability checks, indicating an effort to secure its functionalities.

However, there are notable areas of concern. The presence of 7 AJAX handlers, with 2 of them lacking authentication checks, presents a direct and exploitable risk. While the taint analysis shows no critical or high-severity flows, this can sometimes be due to the limited scope of static analysis and may not capture all potential issues, especially those dependent on external input not analyzed. The vulnerability history being entirely clear is a positive sign, suggesting the developers have a good track record, but it doesn't negate the risks identified in the current static analysis.

In conclusion, while the plugin has strengths in its secure handling of database operations and output, the unprotected AJAX endpoints are a significant weakness that requires immediate attention. The overall security is good but marred by this critical oversight. Addressing the unprotected AJAX handlers is paramount to improving its security.

Key Concerns

  • Unprotected AJAX handlers
Vulnerabilities
None known

Team Builder Showcase Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Team Builder Showcase Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
12
603 escaped
Nonce Checks
18
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

98% escaped615 total outputs
Attack Surface
2 unprotected

Team Builder Showcase Attack Surface

Entry Points9
Unprotected2

AJAX Handlers 7

authwp_ajax_plwl_save_imagesincludes\admin\class-plwl-admin.php:18
authwp_ajax_plwl_save_imageincludes\admin\class-plwl-admin.php:19
authwp_ajax_plwl_autocompleteincludes\admin\class-plwl-admin.php:21
authwp_ajax_plwl_lbu_noticeincludes\admin\class-plwl-admin.php:24
authwp_ajax_plwl_remember_tabincludes\admin\class-plwl-cpt.php:38
authwp_ajax_plwl-edit-noticeincludes\admin\class-plwl-cpt.php:51
authwp_ajax_plwl_shortcode_editorincludes\class-plwl.php:60

Shortcodes 2

[plwl-team] includes\public\class-plwl-shortcode.php:9
[PLWL-TEAM] includes\public\class-plwl-shortcode.php:10
WordPress Hooks 24
actionplwl_admin_tab_generalincludes\admin\class-plwl-admin.php:16
actionplwl_scripts_before_wpincludes\admin\class-plwl-admin.php:20
actiondelete_attachmentincludes\admin\class-plwl-admin.php:22
filteradmin_body_classincludes\admin\class-plwl-admin.php:25
actioninitincludes\admin\class-plwl-cpt.php:23
actionrest_api_initincludes\admin\class-plwl-cpt.php:25
actionload-post.phpincludes\admin\class-plwl-cpt.php:28
actionload-post-new.phpincludes\admin\class-plwl-cpt.php:29
filterget_edit_post_linkincludes\admin\class-plwl-cpt.php:37
actionadd_meta_boxesincludes\admin\class-plwl-cpt.php:149
actionsave_postincludes\admin\class-plwl-cpt.php:152
actionadmin_footerincludes\admin\class-plwl-field-builder.php:13
actionadmin_enqueue_scriptsincludes\class-plwl.php:52
actioninitincludes\class-plwl.php:53
actioninitincludes\class-plwl.php:55
filtermce_buttonsincludes\class-plwl.php:58
filtermce_external_pluginsincludes\class-plwl.php:59
filterupload_mimesincludes\class-plwl.php:63
filterfile_is_displayable_imageincludes\class-plwl.php:64
filterget_user_option_meta-box-order_plwl-team-builder-showcaseincludes\class-plwl.php:119
filterget_user_option_closedpostboxes_plwl-team-builder-showcaseincludes\class-plwl.php:120
filteradmin_body_classincludes\class-plwl.php:121
actionwp_enqueue_scriptsincludes\public\class-plwl-shortcode.php:11
actionadmin_enqueue_scriptsincludes\scripts.php:4
Maintenance & Trust

Team Builder Showcase Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 20, 2025
PHP min version5.6
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs40
Developer Profile

Team Builder Showcase Developer Profile

Pluginwale

1 plugin · 40 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Team Builder Showcase

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/team-buider-showcase/assets/css/team-style.css/wp-content/plugins/team-buider-showcase/assets/js/team-script.js/wp-content/plugins/team-buider-showcase/assets/css/slick.css/wp-content/plugins/team-buider-showcase/assets/css/slick-theme.css/wp-content/plugins/team-buider-showcase/assets/js/slick.min.js/wp-content/plugins/team-buider-showcase/assets/js/waypoints.min.js/wp-content/plugins/team-buider-showcase/assets/js/jquery.counterup.min.js
Script Paths
/wp-content/plugins/team-buider-showcase/assets/js/team-script.js/wp-content/plugins/team-buider-showcase/assets/js/slick.min.js/wp-content/plugins/team-buider-showcase/assets/js/waypoints.min.js/wp-content/plugins/team-buider-showcase/assets/js/jquery.counterup.min.js
Version Parameters
team-buider-showcase/assets/css/team-style.css?ver=team-buider-showcase/assets/js/team-script.js?ver=team-buider-showcase/assets/css/slick.css?ver=team-buider-showcase/assets/css/slick-theme.css?ver=team-buider-showcase/assets/js/slick.min.js?ver=team-buider-showcase/assets/js/waypoints.min.js?ver=team-buider-showcase/assets/js/jquery.counterup.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
plwl-team-showcaseplwl-team-gridplwl-team-sliderplwl-team-memberplwl-team-detailsplwl-team-social-iconsplwl-team-wrapperplwl-team-container
HTML Comments
<!-- Team Builder Showcase Start --><!-- Team Builder Showcase End --><!-- Start Team Member --><!-- End Team Member -->
Data Attributes
data-plwl-team-iddata-plwl-team-layoutdata-plwl-team-styledata-plwl-team-slidesdata-plwl-team-speeddata-plwl-team-autoplay+1 more
JS Globals
plwl_team_paramsplwl_team_settings
REST Endpoints
/wp-json/plwl/v1/teams/wp-json/plwl/v1/team-members
Shortcode Output
[team_builder_showcase][team_builder_showcase id="%d" layout="%s" style="%s" slides="%d" speed="%d" autoplay="%s" navigation="%s"]
FAQ

Frequently Asked Questions about Team Builder Showcase