
Team – Team Members Showcase Plugin Security & Risk Analysis
wordpress.org/plugins/tlp-teamWordPress team plugin to showcase team members with grid, slider, and filterable layouts. Fully compatible with Elementor & Gutenberg.
Is Team – Team Members Showcase Plugin Safe to Use in 2026?
Generally Safe
Score 90/100Team – Team Members Showcase Plugin has a strong security track record. Known vulnerabilities have been patched promptly.
The "tlp-team" v5.0.15 plugin exhibits a mixed security posture. On the positive side, it demonstrates strong adherence to secure coding practices in several areas. The plugin exclusively uses prepared statements for SQL queries, has a very high percentage of properly escaped outputs, and implements a significant number of nonce and capability checks. The absence of critical or high severity taint analysis findings is also a positive indicator. However, notable concerns arise from the attack surface. The plugin exposes 23 entry points, with 2 of these AJAX handlers lacking authentication checks, representing a direct pathway for unauthorized actions if these handlers are exploitable. The vulnerability history is a significant area of concern. While there are no currently unpatched CVEs, the plugin has a history of 5 known vulnerabilities, including 2 high severity ones (SQL Injection and Missing Authorization) and 3 medium severity ones (XSS and Path Traversal). This pattern suggests a recurring tendency for certain types of vulnerabilities, which, despite being patched, indicates potential underlying architectural weaknesses or insufficient security review processes. The presence of the "unserialize" dangerous function is also a potential risk, as improper handling of unserialized data can lead to various vulnerabilities. Overall, while some secure coding practices are in place, the significant attack surface with unprotected entry points and a history of critical vulnerability types necessitate careful attention and ongoing vigilance.
Key Concerns
- Unprotected AJAX handlers
- History of 2 high severity CVEs
- History of 3 medium severity CVEs
- Use of dangerous function: unserialize
- Bundled library: Select2 (potential for outdated version)
Team – Team Members Showcase Plugin Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
Team <= 5.0.10 - Unauthenticated SQL Injection
Team <= 5.0.6 - Missing Authorization
Team – Team Members Showcase Plugin <= 4.4.9 - Missing Authorization to Authenticated (Subscriber+) Settings Update
Team – Team Members Showcase Plugin <= 4.4.1 - Authenticated (Admin+) Stored Cross-Site Scripting
Team - WordPress Team Member Showcase Plugin <= 4.1.1 - Directory Traversal to Arbitrary File Read/Deletion
Team – Team Members Showcase Plugin Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Team – Team Members Showcase Plugin Attack Surface
AJAX Handlers 22
Shortcodes 1
WordPress Hooks 59
Maintenance & Trust
Team – Team Members Showcase Plugin Maintenance & Trust
Maintenance Signals
Community Trust
Team – Team Members Showcase Plugin Alternatives
Team Members Showcase
wps-team
WordPress Team Members Showcase plugin – display staff or team profiles in grids, sliders, tables, or lists with filters, popups, drawers & panels.
Team Members – Multi Language Supported Team Plugin
team-showcase-supreme
Multi-language supported Team Members - Team with Slide is the best plugins to display unlimited team in Carouse and Grid view.
Responsive Team Members Showcase, Team Grid, Team Slider, and Staff List – SmartTeam (formerly WP Team)
team-free
A WordPress plugin to display team members in Carousel, Grid, or List layouts. Customizable.
Dynamic Team Manager – Team Member Showcase with grid, slider, table Elementor widget & shortcode
wp-team-manager
Team plugin to showcase team members, sports rosters, or creative portfolios with grid, list, Slider, table layout. Supports Corporate and Sports Leag …
Ultimate Team Showcase – Advanced WordPress Team Members Plugin
ultimate-team-showcase
The ultimate team member WordPress plugin for showing team members profile in grid, slider, Isotope, and lightbox layouts easily using by shortcodes.
Team – Team Members Showcase Plugin Developer Profile
16 plugins · 213K total installs
How We Detect Team – Team Members Showcase Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tlp-team/assets/css/tlp-team-frontend.css/wp-content/plugins/tlp-team/assets/js/frontend/tlp-team-frontend.js/wp-content/plugins/tlp-team/assets/js/admin/tlp-team-admin.js/wp-content/plugins/tlp-team/assets/js/admin/tlp-admin-taxonomy.jstlp-team/assets/css/tlp-team-frontend.css?ver=tlp-team/assets/js/frontend/tlp-team-frontend.js?ver=tlp-team/assets/js/admin/tlp-team-admin.js?ver=tlp-team/assets/js/admin/tlp-admin-taxonomy.js?ver=HTML / DOM Fingerprints
tlp-team-frontendtlp-team-member-wraptlp-team-isotope-filtertlp-team-member-imagetlp-team-member-infotlp-field-holdermember-field-holdersocialLink<!-- Team Member Info --><!-- Team Member Social Link --><!-- Add new -->data-idid="metaSocialHolder"id="addNewSocial"name="socialttp[tlp-team]