Team Member Team Showcase Security & Risk Analysis

wordpress.org/plugins/team-builder-member-showcase

Display your team members with photos, bios, designations and social links in grid or slider layouts.

2K active installs v0.1.16 PHP 7.2+ WP 5.4+ Updated Dec 27, 2025
meet-the-teamour-teamstaff-directoryteam-memberteam-showcase
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Team Member Team Showcase Safe to Use in 2026?

Generally Safe

Score 100/100

Team Member Team Showcase has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The "team-builder-member-showcase" plugin v0.1.16 exhibits a generally good security posture with several positive indicators. The absence of known vulnerabilities, critical taint flows, dangerous functions, raw SQL queries, file operations, and external HTTP requests are all strong points. The high percentage of properly escaped output further contributes to a robust defense against common injection attacks.

However, a significant concern lies in its attack surface. The presence of one AJAX handler without authentication checks presents a clear risk. While the taint analysis did not flag critical or high severity issues, the two flows with unsanitized paths, even if not currently exploitable or leading to critical issues in this version, indicate potential areas for future vulnerabilities if not addressed. The plugin also lacks capability checks, which, when combined with unprotected entry points, can allow unauthorized users to potentially trigger unintended functionality.

Overall, the plugin benefits from a clean vulnerability history and adherence to secure coding practices in many areas. Nevertheless, the unprotected AJAX endpoint and the observed unsanitized paths in taint analysis warrant attention. Addressing these specific weaknesses would significantly strengthen the plugin's security.

Key Concerns

  • Unprotected AJAX handler
  • Taint flow with unsanitized paths (2 instances)
  • Lack of capability checks
Vulnerabilities
None known

Team Member Team Showcase Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Team Member Team Showcase Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
215 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

98% escaped220 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
tbms_ajax_add_member_li_callback (team-builder-member-showcase.php:321)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Team Member Team Showcase Attack Surface

Entry Points2
Unprotected1

AJAX Handlers 1

authwp_ajax_tbms_add_member_liteam-builder-member-showcase.php:82

Shortcodes 1

[TBMS] shotcode.php:6
WordPress Hooks 9
actioninitteam-builder-member-showcase.php:71
actioninitteam-builder-member-showcase.php:74
actionadd_meta_boxesteam-builder-member-showcase.php:77
actionadmin_initteam-builder-member-showcase.php:80
actionsave_postteam-builder-member-showcase.php:84
actionwidget_textteam-builder-member-showcase.php:87
filtermanage_tbms_cpt_name_posts_columnsteam-builder-member-showcase.php:90
actionmanage_tbms_cpt_name_posts_custom_columnteam-builder-member-showcase.php:93
actionwp_enqueue_scriptsteam-builder-member-showcase.php:95
Maintenance & Trust

Team Member Team Showcase Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 27, 2025
PHP min version7.2
Downloads73K

Community Trust

Rating80/100
Number of ratings5
Active installs2K
Developer Profile

Team Member Team Showcase Developer Profile

A WP Life

61 plugins · 64K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
267 days
View full developer profile
Detection Fingerprints

How We Detect Team Member Team Showcase

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/team-builder-member-showcase/js/tbms-custom.js/wp-content/plugins/team-builder-member-showcase/css/tbms-custom.css
Script Paths
/wp-content/plugins/team-builder-member-showcase/js/tbms-custom.js
Version Parameters
team-builder-member-showcase/js/tbms-custom.js?ver=team-builder-member-showcase/css/tbms-custom.css?ver=

HTML / DOM Fingerprints

CSS Classes
tbms-custom-300tbms-custom-500
Data Attributes
id='tbms_cpt_name-shortcode-value='[TBMS id=
JS Globals
TMCopyShortcode
Shortcode Output
[TBMS id=
FAQ

Frequently Asked Questions about Team Member Team Showcase