Team Manager Unified Security & Risk Analysis

wordpress.org/plugins/team-manager-unified

Manage branch, department, position, and staff information.

0 active installs v1.0.0 PHP + WP + Updated Apr 20, 2025
branchdepartmentlocationstaffteam-manager
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Team Manager Unified Safe to Use in 2026?

Generally Safe

Score 100/100

Team Manager Unified has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The "team-manager-unified" v1.0.0 plugin exhibits a generally good security posture, with no known vulnerabilities in its history and a strong emphasis on secure coding practices like prepared statements and output escaping. The majority of its code signals are positive, indicating a developer who is mindful of security. However, a significant concern arises from the presence of two AJAX handlers that lack authentication checks, creating a direct attack vector. While taint analysis shows no immediate critical or high-severity issues in the current version, the unprotected AJAX endpoints represent a potential entry point for malicious actors to exploit if further vulnerabilities exist or are introduced.

The plugin's history of zero CVEs is a positive indicator of its development quality and the diligence of its maintainers. The use of Select2 as a bundled library is noted, but without version information, its security can't be fully assessed; however, this is a common practice. The total number of entry points is moderate, and the lack of REST API routes or cron events further limits the attack surface. Despite the strengths in its development practices and vulnerability history, the two unprotected AJAX handlers necessitate a cautious approach to its deployment and require immediate attention.

Key Concerns

  • Unprotected AJAX handlers
Vulnerabilities
None known

Team Manager Unified Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Team Manager Unified Code Analysis

Dangerous Functions
0
Raw SQL Queries
5
35 prepared
Unescaped Output
24
125 escaped
Nonce Checks
14
Capability Checks
5
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

88% prepared40 total queries

Output Escaping

84% escaped149 total outputs
Data Flows
All sanitized

Data Flow Analysis

7 flows
temaun_delete_department (controllers\DepartmentController.php:116)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Team Manager Unified Attack Surface

Entry Points18
Unprotected2

AJAX Handlers 17

authwp_ajax_temaun_get_branchescontrollers\BranchController.php:17
authwp_ajax_temaun_save_branchcontrollers\BranchController.php:18
authwp_ajax_temaun_delete_branchcontrollers\BranchController.php:19
authwp_ajax_temaun_get_departmentscontrollers\DepartmentController.php:21
authwp_ajax_temaun_save_departmentcontrollers\DepartmentController.php:22
authwp_ajax_temaun_delete_departmentcontrollers\DepartmentController.php:23
authwp_ajax_temaun_get_branches_for_dropdowncontrollers\DepartmentController.php:24
authwp_ajax_temaun_get_positionscontrollers\PositionController.php:21
authwp_ajax_temaun_save_positioncontrollers\PositionController.php:22
authwp_ajax_temaun_delete_positioncontrollers\PositionController.php:23
authwp_ajax_temaun_get_departments_for_dropdowncontrollers\PositionController.php:24
authwp_ajax_temaun_get_staffcontrollers\StaffController.php:22
authwp_ajax_temaun_save_staffcontrollers\StaffController.php:23
authwp_ajax_temaun_delete_staffcontrollers\StaffController.php:24
authwp_ajax_temaun_get_wp_userscontrollers\StaffController.php:25
authwp_ajax_temaun_get_positions_by_staffcontrollers\StaffController.php:27
noprivwp_ajax_temaun_get_positions_by_staffcontrollers\StaffController.php:28

Shortcodes 1

[team_manager_unified_staff] inc\integrations\builders\flatsome\shortcodes\staff.php:218
WordPress Hooks 10
actionwp_headinc\core\schemas.php:9
actionux_builder_setupinc\integrations\builders\flatsome\builder\builder.php:9
actionadmin_menuteam-manager-unified.php:47
actionadmin_enqueue_scriptsteam-manager-unified.php:48
actionadmin_initteam-manager-unified.php:50
actionwp_enqueue_scriptsteam-manager-unified.php:68
actionplugins_loadedteam-manager-unified.php:70
actioninitteam-manager-unified.php:73
filtertheme_mod_blog_author_boxteam-manager-unified.php:83
filterthe_contentteam-manager-unified.php:86
Maintenance & Trust

Team Manager Unified Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 20, 2025
PHP min version
Downloads347

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Team Manager Unified Developer Profile

polyxgo

6 plugins · 170 total installs

92
trust score
Avg Security Score
97/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Team Manager Unified

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/team-manager-unified/dist/assets/css/public/style.min.css
Script Paths
/wp-content/plugins/team-manager-unified/dist/assets/js/libs/select2/4.1.0/select2.min.js/wp-content/plugins/team-manager-unified/dist/assets/css/libs/select2/4.1.0/select2.min.css
Version Parameters
team-manager-unified/dist/assets/css/public/style.min.css?ver=team-manager-unified/dist/assets/css/libs/select2/4.1.0/select2.min.css?ver=team-manager-unified/dist/assets/js/libs/select2/4.1.0/select2.min.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-temaun-staff-iddata-temaun-branch-iddata-temaun-department-iddata-temaun-position-id
JS Globals
temaun_settings
REST Endpoints
/wp-json/temaun/v1/staff/wp-json/temaun/v1/branches/wp-json/temaun/v1/departments/wp-json/temaun/v1/positions
FAQ

Frequently Asked Questions about Team Manager Unified