Team Members Security & Risk Analysis

wordpress.org/plugins/team-members

A responsive and clean way to display your team. Create members, add their positions, bios (and more...) and copy-paste the shortcode anywhere.

20K active installs v5.4.1 PHP + WP 3.6+ Updated Jan 29, 2026
meet-the-teamresponsiveshortcodeteamteams
96
A · Safe
CVEs total5
Unpatched0
Last CVESep 26, 2025
Safety Verdict

Is Team Members Safe to Use in 2026?

Generally Safe

Score 96/100

Team Members has a strong security track record. Known vulnerabilities have been patched promptly.

5 known CVEsLast CVE: Sep 26, 2025Updated 2mo ago
Risk Assessment

The static analysis of "team-members" v5.4.1 reveals a generally strong security posture. The plugin demonstrates excellent adherence to secure coding practices, with all SQL queries utilizing prepared statements, 100% of output being properly escaped, and the absence of dangerous functions, file operations, and external HTTP requests. The presence of nonce and capability checks on its single entry point (a shortcode) further bolsters its security by ensuring proper authorization. Taint analysis shows no concerning flows, indicating a low risk of immediate code-level vulnerabilities.

Key Concerns

  • Multiple Medium CVEs historically
  • Past XSS vulnerabilities
Vulnerabilities
5

Team Members Security Vulnerabilities

CVEs by Year

2 CVEs in 2022
2022
2 CVEs in 2024
2024
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
5

5 total CVEs

CVE-2025-8440medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Team Members <= 5.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

Sep 26, 2025 Patched in 5.3.6 (1d)
CVE-2024-38670medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Team Members <= 5.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

Jul 10, 2024 Patched in 5.3.4 (9d)
CVE-2024-1331medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Team Members <= 5.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

Feb 26, 2024 Patched in 5.3.2 (362d)
CVE-2022-3936medium · 5.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Team Members <= 5.2.0 - Authenticated (Editor+) Stored Cross-Site Scripting

Dec 9, 2022 Patched in 5.2.1 (410d)
CVE-2022-1568medium · 5.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Team Members <= 5.1.0 - Authenticated (Admin+) Stored Cross-Site Scripting

May 9, 2022 Patched in 5.1.1 (624d)
Code Analysis
Analyzed Mar 16, 2026

Team Members Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
116 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped116 total outputs
Attack Surface

Team Members Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[tmm] inc\tmm-shortcode.php:4
WordPress Hooks 14
actionadmin_enqueue_scriptsinc\tmm-admin-scripts.php:4
actionwp_enqueue_scriptsinc\tmm-front-scripts.php:4
actionadmin_initinc\tmm-metaboxes-help.php:4
actionadmin_initinc\tmm-metaboxes-members.php:31
actionadmin_initinc\tmm-metaboxes-pro.php:4
actionadmin_initinc\tmm-metaboxes-settings.php:70
actioninitinc\tmm-post-type.php:4
filterpost_updated_messagesinc\tmm-post-type.php:44
actionadmin_initinc\tmm-pro-version-check.php:4
actionadmin_noticesinc\tmm-pro-version-check.php:11
actionsave_postinc\tmm-save-metaboxes.php:4
actionmanage_tmm_posts_custom_columninc\tmm-shortcode-column.php:4
filtermanage_tmm_posts_columnsinc\tmm-shortcode-column.php:20
actionplugins_loadedinc\tmm-text-domain.php:4
Maintenance & Trust

Team Members Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 29, 2026
PHP min version
Downloads762K

Community Trust

Rating84/100
Number of ratings53
Active installs20K
Developer Profile

Team Members Developer Profile

WP Darko

8 plugins · 59K total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
175 days
View full developer profile
Detection Fingerprints

How We Detect Team Members

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/team-members/dmb/dmb.min.css/wp-content/plugins/team-members/css/tmm_style.min.css/wp-content/plugins/team-members/dmb/dmb.js/wp-content/plugins/team-members/css/tmm_style.css
Script Paths
/wp-content/plugins/team-members/dmb/dmb.js
Version Parameters
team-members/dmb/dmb.min.css?ver=team-members/css/tmm_style.min.css?ver=team-members/dmb/dmb.js?ver=team-members/css/tmm_style.css?ver=

HTML / DOM Fingerprints

CSS Classes
tmmtmm_wraptmm_membertmm_phototmm_textblocktmm_namestmm_fnametmm_lname+3 more
Data Attributes
data-tmm-member-iddata-tmm-edit-link
JS Globals
objectL10n
Shortcode Output
<div class="tmm tmm__columns tmm_wrap<div class="tmm_container"><div class="tmm_member"
FAQ

Frequently Asked Questions about Team Members