Tour Operator Team Security & Risk Analysis

wordpress.org/plugins/tour-operator-team

The Tour Operator Team plugins adds the “Team” post type, which you can display front-and-centre on your site.

10 active installs v2.1 PHP 8.0+ WP 6.7+ Updated Dec 20, 2025
lsxour-teamteamteam-memberstour-operator
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Tour Operator Team Safe to Use in 2026?

Generally Safe

Score 100/100

Tour Operator Team has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The "tour-operator-team" plugin v2.1 exhibits a strong security posture based on the provided static analysis. The absence of identified AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the code signals indicate robust security practices, with 100% of SQL queries using prepared statements, a very high rate of output escaping (99%), and the presence of a nonce check. The lack of dangerous functions, file operations, and external HTTP requests further reduces potential vulnerabilities.

The plugin's vulnerability history is also clear, with no known CVEs recorded. This, combined with the clean static analysis, suggests a well-maintained and secure plugin. The lack of any critical or high-severity taint flows is a positive indicator. However, the complete absence of capability checks, while not a direct flaw in itself, means that access control is likely handled entirely by WordPress core, which is generally acceptable but could be a point of failure if WordPress core itself has vulnerabilities. Overall, the plugin appears to be very secure, with no immediate exploitable flaws identified.

Vulnerabilities
None known

Tour Operator Team Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Tour Operator Team Release Timeline

v2.1Current
v2.0.0
v1.2.7
v1.2.6
v1.2.5
v1.2.4
v1.2.3
v1.2.2
v1.2.1
v1.1.2
v1.1.1
v1.1.0
Code Analysis
Analyzed Apr 16, 2026

Tour Operator Team Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
1
71 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

99% escaped72 total outputs
Attack Surface

Tour Operator Team Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 26
actioninitclasses/class-to-team-admin.php:33
actioninitclasses/class-to-team-admin.php:34
actioncmb2_admin_initclasses/class-to-team-admin.php:35
filterlsx_get_taxonomies_configsclasses/class-to-team-admin.php:37
filterlsx_to_post_custom_fieldsclasses/class-to-team-admin.php:39
filterlsx_to_destination_custom_fieldsclasses/class-to-team-admin.php:40
filterlsx_to_tour_custom_fieldsclasses/class-to-team-admin.php:41
filterlsx_to_accommodation_custom_fieldsclasses/class-to-team-admin.php:42
filterlsx_to_special_custom_fieldsclasses/class-to-team-admin.php:44
filterlsx_to_review_custom_fieldsclasses/class-to-team-admin.php:45
filterlsx_to_activity_custom_fieldsclasses/class-to-team-admin.php:46
actioncreate_termclasses/class-to-team-admin.php:60
actionedit_termclasses/class-to-team-admin.php:61
filterposts_orderbyclasses/class-to-team-frontend.php:41
filterlsx_to_maps_argsclasses/class-to-team-frontend.php:44
filterlsx_to_has_maps_locationclasses/class-to-team-frontend.php:45
actioninitclasses/class-to-team-templates.php:26
actionactivated_pluginclasses/class-to-team.php:65
actioninitclasses/class-to-team.php:67
filterlsx_to_framework_post_typesclasses/class-to-team.php:70
filterlsx_to_post_typesclasses/class-to-team.php:71
filterlsx_to_post_types_singularclasses/class-to-team.php:72
filterlsx_to_framework_taxonomiesclasses/class-to-team.php:75
filterlsx_to_framework_taxonomies_pluralclasses/class-to-team.php:76
actionadmin_initclasses/class-to-team.php:89
filterwpseo_schema_graph_piecesclasses/class-to-team.php:90
Maintenance & Trust

Tour Operator Team Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 20, 2025
PHP min version8.0
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Tour Operator Team Developer Profile

Ash Shaw

17 plugins · 710 total installs

81
trust score
Avg Security Score
90/100
Avg Patch Time
51 days
View full developer profile
Detection Fingerprints

How We Detect Tour Operator Team

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tour-operator-team/assets/css/frontend.css/wp-content/plugins/tour-operator-team/assets/js/frontend.js
Script Paths
/wp-content/plugins/tour-operator-team/assets/js/frontend.js
Version Parameters
tour-operator-team/assets/css/frontend.css?ver=tour-operator-team/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
lsx-to-team-memberteam-member-wraplsx-to-team-galleryteam-single-wrapteam-member-contentteam-member-info
Data Attributes
data-team-member-id
JS Globals
LSX_TO_Team
Shortcode Output
[team_members][team_member]
FAQ

Frequently Asked Questions about Tour Operator Team