Team MXT – Team Member Showcase Security & Risk Analysis

wordpress.org/plugins/team-mxt

Team MXT is a WordPress team member plugin that allows you to showcase your team members with customizable profiles, layouts, and integrations.

0 active installs v1.0.0 PHP 7.0+ WP 5.2+ Updated Unknown
teamteam-member-pluginteam-membersteam-pluginteam-showcase
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Team MXT – Team Member Showcase Safe to Use in 2026?

Generally Safe

Score 100/100

Team MXT – Team Member Showcase has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "team-mxt" v1.0.0 plugin exhibits a generally good security posture based on the provided static analysis. The absence of known vulnerabilities in its history, coupled with a strong adherence to secure coding practices like the use of prepared statements for all SQL queries and near-perfect output escaping, indicates a conscientious development effort. The plugin also implements a healthy number of nonce and capability checks, reinforcing its defensive measures.

However, a significant concern arises from the attack surface analysis, which reveals one unprotected AJAX handler. This represents a direct entry point that could be exploited if malicious data is passed without proper authentication or authorization checks. While taint analysis did not flag critical or high-severity issues, the presence of one flow with unsanitized paths warrants attention, as it could potentially lead to vulnerabilities depending on the context of the data manipulation.

Overall, the "team-mxt" plugin is well-developed with strong security fundamentals. The primary weakness lies in the unprotected AJAX handler, which, if exploitable, could undermine the otherwise robust security of the plugin. The lack of past vulnerabilities is a positive indicator, but the identified unprotected entry point necessitates immediate remediation to maintain a secure environment.

Key Concerns

  • Unprotected AJAX handler
  • Flow with unsanitized path
Vulnerabilities
None known

Team MXT – Team Member Showcase Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Team MXT – Team Member Showcase Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
358 escaped
Nonce Checks
18
Capability Checks
9
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

99% escaped362 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

6 flows1 with unsanitized paths
<edit-member> (edit-member.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Team MXT – Team Member Showcase Attack Surface

Entry Points5
Unprotected1

AJAX Handlers 2

authwp_ajax_team_mxt_live_previewteam-mxt.php:32
authwp_ajax_team_mxt_unique_live_previewteam-mxt.php:40

Shortcodes 3

[team_mxt] team-mxt.php:38
[team_mxt_members] team-mxt.php:228
[team_mxt_without_slider] team-mxt.php:229
WordPress Hooks 24
actionwp_enqueue_scriptspartials\carousel.php:8
actionadmin_enqueue_scriptsteam-mxt.php:28
actionadmin_enqueue_scriptsteam-mxt.php:29
actionadmin_menuteam-mxt.php:30
actionadmin_initteam-mxt.php:31
actionadmin_post_team_mxt_save_memberteam-mxt.php:33
actionadmin_initteam-mxt.php:34
actionadmin_post_team_mxt_update_memberteam-mxt.php:35
actionadmin_enqueue_scriptsteam-mxt.php:36
actioninitteam-mxt.php:37
actioninitteam-mxt.php:39
actionwp_enqueue_scriptsteam-mxt.php:41
actionwp_enqueue_scriptsteam-mxt.php:42
actionadmin_enqueue_scriptsteam-mxt.php:43
actionadmin_enqueue_scriptsteam-mxt.php:44
actionwp_enqueue_scriptsteam-mxt.php:45
actionadmin_enqueue_scriptsteam-mxt.php:46
actionadmin_enqueue_scriptsteam-mxt.php:47
actionadmin_enqueue_scriptsteam-mxt.php:48
actionadmin_enqueue_scriptsteam-mxt.php:49
actionadmin_enqueue_scriptsteam-mxt.php:50
actionadmin_enqueue_scriptsteam-mxt.php:51
actionwp_enqueue_scriptsteam-mxt.php:268
actionwp_enqueue_scriptsteam-mxt.php:313
Maintenance & Trust

Team MXT – Team Member Showcase Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedUnknown
PHP min version7.0
Downloads868

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

Team MXT – Team Member Showcase Developer Profile

Raju Ahmed

2 plugins · 0 total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Team MXT – Team Member Showcase

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/team-mxt/css/all.min.css/wp-content/plugins/team-mxt/css/admin-style.css/wp-content/plugins/team-mxt/css/popup.css/wp-content/plugins/team-mxt/js/admin-scripts.js
Script Paths
/wp-content/plugins/team-mxt/js/admin-scripts.js
Version Parameters
team-mxt-admin-style?ver=team-mxt-popup?ver=

HTML / DOM Fingerprints

CSS Classes
team_mxt_display_members_wrapperteam_mxt_member_itemteam_mxt_member_imageteam_mxt_member_nameteam_mxt_member_positionteam_mxt_member_descriptionteam_mxt_social_iconteam_mxt_edit_member_form+1 more
HTML Comments
<!-- Team MXT Plugin --><!-- End Team MXT Plugin --><!-- Member Item Start --><!-- Member Item End -->
Data Attributes
data-member-iddata-action="delete_member"data-nonce="delete_member_nonce"
JS Globals
team_mxt_data
REST Endpoints
/wp-json/team-mxt/v1/members
Shortcode Output
[team_mxt]<div class="team_mxt_display_members_wrapper">
FAQ

Frequently Asked Questions about Team MXT – Team Member Showcase