Team Section Block – Showcase Team Members with Layout Options Security & Risk Analysis

wordpress.org/plugins/team-section

Showcase your team members in various layouts and designs.

1K active installs v2.0.2 PHP 7.1+ WP 6.5+ Updated Apr 12, 2026
blockmembersteamteam-builderteam-members
98
A · Safe
CVEs total2
Unpatched0
Last CVEJan 16, 2026
Download
Safety Verdict

Is Team Section Block – Showcase Team Members with Layout Options Safe to Use in 2026?

Generally Safe

Score 98/100

Team Section Block – Showcase Team Members with Layout Options has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

2 known CVEsLast CVE: Jan 16, 2026Updated 1mo ago
Risk Assessment

The "team-section" plugin v2.0.2 exhibits a generally strong security posture based on the static analysis. The absence of dangerous functions, the consistent use of prepared statements for SQL queries, and a high percentage of properly escaped output are positive indicators. Furthermore, the presence of nonce and capability checks on entry points suggests an effort to protect against common web vulnerabilities. The plugin also demonstrates good practice by not directly performing file operations or making external HTTP requests without apparent sanitization. The limited attack surface, with no immediately identifiable unprotected entry points, further contributes to its perceived safety.

However, a review of past vulnerabilities reveals a history of two medium-severity Cross-Site Scripting (XSS) issues, with the most recent one being in the future, which is a data anomaly. While there are currently no unpatched CVEs, this history of XSS vulnerabilities, even if resolved, indicates a potential for input sanitization weaknesses that could be re-introduced. The presence of bundled libraries, specifically Freemius, could also pose a risk if these libraries are not regularly updated and are found to have vulnerabilities.

In conclusion, the "team-section" plugin v2.0.2 appears to follow many security best practices, particularly in its code execution and data handling. The main concern stems from its past XSS vulnerabilities, which warrant vigilance, and the potential risks associated with bundled libraries. The future vulnerability date is a significant anomaly that needs clarification or correction to accurately assess the current risk.

Key Concerns

  • History of medium severity XSS vulnerabilities
  • Bundled library (Freemius) detected
  • Anomalous future vulnerability date
Vulnerabilities
2 published

Team Section Block – Showcase Team Members with Layout Options Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2026-0833medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Team Section Block <= 2.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Social Network Link

Jan 16, 2026 Patched in 2.0.1 (1d)
CVE-2025-26949medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Team Section Block <= 1.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

Feb 23, 2025 Patched in 1.1.0 (9d)
Version History

Team Section Block – Showcase Team Members with Layout Options Release Timeline

Code Analysis
Analyzed Mar 16, 2026

Team Section Block – Showcase Team Members with Layout Options Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
44 escaped
Nonce Checks
4
Capability Checks
6
File Operations
0
External Requests
1
Bundled Libraries
1

Bundled Libraries

Freemius

Output Escaping

98% escaped45 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
fs_init (freemius-lite\inc\Base\FSActivate.php:68)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Team Section Block – Showcase Team Members with Layout Options Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 1

authwp_ajax_fs_initfreemius-lite\inc\Base\FSActivate.php:42

Shortcodes 1

[tsb] includes\ShortCode.php:7
WordPress Hooks 20
actionadmin_headfreemius-lite\inc\Base\FSActivate.php:29
actionadmin_enqueue_scriptsfreemius-lite\inc\Base\FSActivate.php:30
actionadmin_menufreemius-lite\inc\Base\FSActivate.php:33
actionadmin_footerfreemius-lite\inc\Base\FSActivate.php:38
actionadmin_footerfreemius-lite\inc\Base\FSActivate.php:39
actionadmin_noticesfreemius-lite\inc\Base\FSActivate.php:44
actioninitfreemius-lite\inc\Base\FS_Lite.php:29
actionadmin_menuincludes\AdminMenu.php:8
actionadmin_enqueue_scriptsincludes\AdminMenu.php:9
actionadmin_enqueue_scriptsincludes\ShortCode.php:8
actioninitincludes\ShortCode.php:9
filtermanage_tsb_posts_columnsincludes\ShortCode.php:10
actionmanage_tsb_posts_custom_columnincludes\ShortCode.php:11
actionuse_block_editor_for_postincludes\ShortCode.php:13
actionenqueue_block_assetsindex.php:73
actioninitindex.php:74
actionenqueue_block_editor_assetsindex.php:75
actionwp_enqueue_scriptsindex.php:76
filterdefault_titleindex.php:77
filterdefault_contentindex.php:83
Maintenance & Trust

Team Section Block – Showcase Team Members with Layout Options Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 12, 2026
PHP min version7.1
Downloads19K

Community Trust

Rating60/100
Number of ratings1
Active installs1K
Developer Profile

Team Section Block – Showcase Team Members with Layout Options Developer Profile

colorlibplugins

121 plugins · 740K total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
130 days
View full developer profile
Detection Fingerprints

How We Detect Team Section Block – Showcase Team Members with Layout Options

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/team-section/assets/css/font-awesome.min.css
Version Parameters
team-section/style.css?ver=team-section/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
ts-team-section-wrapperts-team-member-itemts-member-social-linkts-member-details
Data Attributes
data-team-section-iddata-team-member-iddata-animationdata-autoplaydata-autoplay-speeddata-loop
JS Globals
tsbIsPremiumtsmbpipecheck
Shortcode Output
[team_section][team_member]
FAQ

Frequently Asked Questions about Team Section Block – Showcase Team Members with Layout Options