Team Showcase – Responsive Team Members Grid, Slider & Carousel Plugin Security & Risk Analysis

wordpress.org/plugins/team-showcase

Create beautiful, responsive team member sections with grid, slider, list, popup, and carousel layouts. Perfect for companies, agencies, startups, sch …

2K active installs v3.0.0 PHP + WP 4.0+ Updated Feb 8, 2026
employeestaffteam-gridteam-membersteam-showcase
98
A · Safe
CVEs total2
Unpatched0
Last CVEDec 30, 2025
Safety Verdict

Is Team Showcase – Responsive Team Members Grid, Slider & Carousel Plugin Safe to Use in 2026?

Generally Safe

Score 98/100

Team Showcase – Responsive Team Members Grid, Slider & Carousel Plugin has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Dec 30, 2025Updated 1mo ago
Risk Assessment

The "team-showcase" v3.0.0 plugin exhibits a generally strong security posture with several positive indicators. The absence of dangerous functions, file operations, and external HTTP requests is commendable. Furthermore, all SQL queries are properly prepared, and there's a robust application of nonces and capability checks, indicating good development practices for handling user input and preventing unauthorized actions. The static analysis shows a low percentage of unescaped output (22%), which, while not zero, is a relatively small concern given the total volume of output operations.

However, the plugin's vulnerability history reveals two known medium-severity CVEs, both related to Cross-Site Scripting (XSS). While currently unpatched CVEs are zero, the recurring nature of XSS vulnerabilities suggests a potential for them to reappear if not addressed rigorously in future development. The absence of any taint analysis results, while seemingly positive, might also indicate that the analysis performed did not cover all potential attack vectors or that the plugin's structure did not lend itself to the specific taint analysis methodology used. The limited attack surface (2 entry points) and the fact that they are protected is a significant strength.

In conclusion, "team-showcase" v3.0.0 has several security strengths, particularly in its handling of database operations and authentication. The primary area of concern stems from its past XSS vulnerabilities, which warrant continued vigilance. The development team has demonstrated awareness of security best practices, but the historical context of XSS issues suggests a need for ongoing code review and secure coding training to prevent recurrence.

Key Concerns

  • Known medium severity XSS vulnerabilities
  • Percentage of unescaped output
Vulnerabilities
2

Team Showcase – Responsive Team Members Grid, Slider & Carousel Plugin Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2025-69335medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Team Showcase <= 2.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

Dec 30, 2025 Patched in 3.0.0 (15d)
CVE-2023-5639medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Team Showcase <= 2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

Oct 18, 2023 Patched in 2.2 (97d)
Code Analysis
Analyzed Mar 16, 2026

Team Showcase – Responsive Team Members Grid, Slider & Carousel Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
209
744 escaped
Nonce Checks
4
Capability Checks
7
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

78% escaped953 total outputs
Attack Surface

Team Showcase – Responsive Team Members Grid, Slider & Carousel Plugin Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 1

authwp_ajax_tmffree_team_dismiss_review_noticeadmin\team-manager-free-meta-boxes.php:526

Shortcodes 1

[tmfshortcode] includes\shortcodes\team-shortcode.php:203
WordPress Hooks 25
actionadd_meta_boxesadmin\team-manager-free-meta-boxes.php:47
actionsave_postadmin\team-manager-free-meta-boxes.php:145
actionsave_postadmin\team-manager-free-meta-boxes.php:388
actionadmin_noticesadmin\team-manager-free-meta-boxes.php:506
actionedit_form_after_titleadmin\team-manager-free-meta-boxes.php:577
actioninitadmin\team-manager-free-post-type.php:61
actioninitadmin\team-manager-free-post-type.php:83
filterenter_title_hereadmin\team-manager-free-post-type.php:92
filteradmin_post_thumbnail_htmladmin\team-manager-free-post-type.php:104
filterpost_updated_messagesadmin\team-manager-free-post-type.php:123
actioninitadmin\team-manager-free-post-type.php:167
filterenter_title_hereadmin\team-manager-free-post-type.php:176
filterpost_updated_messagesadmin\team-manager-free-post-type.php:195
filtermanage_team_mf_posts_columnsadmin\team-manager-free-post-type.php:255
actionmanage_team_mf_posts_custom_columnadmin\team-manager-free-post-type.php:256
filtermanage_team_mf_team_posts_columnsadmin\team-manager-free-post-type.php:271
actionmanage_team_mf_team_posts_custom_columnadmin\team-manager-free-post-type.php:279
actionadd_meta_boxesadmin\team-manager-free-post-type.php:289
actionsave_postadmin\team-manager-free-post-type.php:2924
filterwidget_textteam-manager-free.php:27
actionplugins_loadedteam-manager-free.php:33
actionwp_enqueue_scriptsteam-manager-free.php:50
actionadmin_enqueue_scriptsteam-manager-free.php:78
actionadmin_menuteam-manager-free.php:129
actionadmin_initteam-manager-free.php:154
Maintenance & Trust

Team Showcase – Responsive Team Members Grid, Slider & Carousel Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 8, 2026
PHP min version
Downloads106K

Community Trust

Rating68/100
Number of ratings24
Active installs2K
Developer Profile

Team Showcase – Responsive Team Members Grid, Slider & Carousel Plugin Developer Profile

Themepoints

19 plugins · 10K total installs

84
trust score
Avg Security Score
94/100
Avg Patch Time
66 days
View full developer profile
Detection Fingerprints

How We Detect Team Showcase – Responsive Team Members Grid, Slider & Carousel Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/team-showcase/assets/css/font-awesome.css/wp-content/plugins/team-showcase/assets/css/fontello.css/wp-content/plugins/team-showcase/assets/css/magnific-popup.css/wp-content/plugins/team-showcase/assets/css/team-frontend.css/wp-content/plugins/team-showcase/assets/css/style1.css/wp-content/plugins/team-showcase/assets/js/jquery.magnific-popup.js/wp-content/plugins/team-showcase/assets/js/main.js/wp-content/plugins/team-showcase/admin/css/team-manager-backend.css+3 more
Script Paths
/wp-content/plugins/team-showcase/assets/js/jquery.magnific-popup.js/wp-content/plugins/team-showcase/assets/js/main.js/wp-content/plugins/team-showcase/admin/js/color-picker.js/wp-content/plugins/team-showcase/admin/js/team-manager-free-admin.js
Version Parameters
team-showcase/assets/js/jquery.magnific-popup.js?ver=team-showcase/assets/js/main.js?ver=team-showcase/admin/js/color-picker.js?ver=team-showcase/admin/js/team-manager-free-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
team-members-wrap
Data Attributes
data-mfp-src
FAQ

Frequently Asked Questions about Team Showcase – Responsive Team Members Grid, Slider & Carousel Plugin