Team Master – A Modern WordPress Team Showcase Security & Risk Analysis

wordpress.org/plugins/team-master

The functionality of this all-new “Team Master” plugin goes way beyond just display your team. There are a lot of customization options to change the …

30 active installs v1.1.2 PHP 7.0+ WP 4.0+ Updated Mar 26, 2022
carouselour-teamteam-masterteamswordpress-team-showcase
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Team Master – A Modern WordPress Team Showcase Safe to Use in 2026?

Generally Safe

Score 85/100

Team Master – A Modern WordPress Team Showcase has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The team-master plugin v1.1.2 exhibits a mixed security posture. On one hand, the absence of known vulnerabilities and the exclusive use of prepared statements for SQL queries are positive indicators. The plugin also demonstrates a good number of output escaping calls, although the overall percentage is concerning. However, a significant weakness lies in its attack surface. A substantial number of AJAX handlers, specifically 6 out of 6, lack authentication checks. This creates a direct pathway for unauthenticated users to interact with potentially sensitive functionalities. The limited number of nonce checks also contributes to this elevated risk. While no critical taint flows or dangerous functions were identified, the unauthenticated AJAX endpoints represent a clear and present danger. The plugin's history of zero vulnerabilities is a strength, but it doesn't negate the immediate risks identified in the static analysis. In conclusion, while the plugin has avoided past security issues and uses secure SQL practices, the lack of authentication on its AJAX endpoints is a critical flaw that requires immediate attention.

Key Concerns

  • Unprotected AJAX handlers
  • Low percentage of properly escaped output
  • Limited nonce checks
Vulnerabilities
None known

Team Master – A Modern WordPress Team Showcase Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Team Master – A Modern WordPress Team Showcase Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
313
208 escaped
Nonce Checks
3
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

40% escaped521 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
tm_retrive_modal (public\class-team-master-public.php:146)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
6 unprotected

Team Master – A Modern WordPress Team Showcase Attack Surface

Entry Points7
Unprotected6

AJAX Handlers 6

authwp_ajax_tm_retrive_membersincludes\class-team-master.php:175
noprivwp_ajax_tm_retrive_membersincludes\class-team-master.php:176
authwp_ajax_tm_retrive_modalincludes\class-team-master.php:195
noprivwp_ajax_tm_retrive_modalincludes\class-team-master.php:196
authwp_ajax_tm_ajax_members_loadmoreincludes\class-team-master.php:197
noprivwp_ajax_tm_ajax_members_loadmoreincludes\class-team-master.php:198

Shortcodes 1

[team_master] includes\class-team-master.php:193
WordPress Hooks 18
actionadmin_initadmin\team\team-master-vc-shortcode.php:59
actionplugins_loadedincludes\class-team-master.php:150
actionadmin_enqueue_scriptsincludes\class-team-master.php:164
actionadmin_enqueue_scriptsincludes\class-team-master.php:165
actioninitincludes\class-team-master.php:168
actionadd_meta_boxesincludes\class-team-master.php:169
actionsave_postincludes\class-team-master.php:170
filtermanage_tm_members_posts_columnsincludes\class-team-master.php:171
actionmanage_tm_members_posts_custom_columnincludes\class-team-master.php:172
actionadmin_menuincludes\class-team-master.php:173
actionadmin_menuincludes\class-team-master.php:174
actionadmin_initincludes\class-team-master.php:177
actionwp_enqueue_scriptsincludes\class-team-master.php:191
actionwp_enqueue_scriptsincludes\class-team-master.php:192
actionwp_footerincludes\class-team-master.php:194
filterarchive_templateincludes\class-team-master.php:199
filtersingle_templateincludes\class-team-master.php:200
actionupgrader_process_completeteam-master.php:112
Maintenance & Trust

Team Master – A Modern WordPress Team Showcase Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.13
Last updatedMar 26, 2022
PHP min version7.0
Downloads3K

Community Trust

Rating100/100
Number of ratings2
Active installs30
Developer Profile

Team Master – A Modern WordPress Team Showcase Developer Profile

Adnan Moqsood

1 plugin · 30 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Team Master – A Modern WordPress Team Showcase

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/team-master/admin/css/team-master-admin.css/wp-content/plugins/team-master/admin/css/select2.min.css/wp-content/plugins/team-master/public/css/team-master.css/wp-content/plugins/team-master/public/js/team-master.js
Script Paths
https://maxcdn.bootstrapcdn.com/font-awesome/4.7.0/css/font-awesome.min.css
Version Parameters
team-master-admin.css?ver=select2.min.css?ver=team-master.css?ver=team-master.js?ver=

HTML / DOM Fingerprints

CSS Classes
tm_member_sectiontm_member_imagetm_member_detailstm_member_nametm_member_designationtm_member_description
HTML Comments
<!-- START TEAM MASTER SHORTCODE --><!-- END TEAM MASTER SHORTCODE --><!-- START TEAM MASTER WIDGET --><!-- END TEAM MASTER WIDGET -->
Data Attributes
data-tm-style
JS Globals
teamMasterPublic
Shortcode Output
[team_master][team_master_widget]
FAQ

Frequently Asked Questions about Team Master – A Modern WordPress Team Showcase