
Team List Security & Risk Analysis
wordpress.org/plugins/wp-team-listDisplay your teammates anywhere on your WordPress site using this easy-to-use plugin.
Is Team List Safe to Use in 2026?
Generally Safe
Score 92/100Team List has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-team-list plugin version 4.0.0 exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of any known CVEs, coupled with a clean taint analysis and a low number of entry points, suggests a well-maintained and secure codebase. The plugin demonstrates good security practices, with all SQL queries utilizing prepared statements and a high percentage of output escaping. Nonce and capability checks are also present, further strengthening its defenses against common WordPress attacks.
While the plugin is generally secure, there are minor areas for consideration. The presence of two shortcodes as entry points, although not identified as unprotected in this analysis, always introduces a potential attack vector that requires careful implementation to prevent issues like cross-site scripting (XSS) if not properly handled. The 90% output escaping rate, while good, leaves a small margin for potential unescaped outputs, which could be a vector for XSS if the remaining 10% involves user-controlled data.
Overall, wp-team-list v4.0.0 appears to be a robust and secure plugin. Its strong track record of no vulnerabilities and adherence to secure coding practices like prepared statements and capability checks are significant strengths. The limited attack surface and lack of critical code signals are highly positive. Any minor concerns, such as potential for unescaped output, are within acceptable limits for a plugin with this history and analysis.
Key Concerns
- Potential unescaped output (10%)
Team List Security Vulnerabilities
Team List Code Analysis
SQL Query Safety
Output Escaping
Team List Attack Surface
Shortcodes 2
WordPress Hooks 17
Maintenance & Trust
Team List Maintenance & Trust
Maintenance Signals
Community Trust
Team List Alternatives
User Box
users-box
Plugin provides a widget for displaying avatars of registered users.
SiteOrigin Widgets Bundle
so-widgets-bundle
Essential elements for modern websites. Add buttons, sliders, heroes, maps, images, carousels, features, icons, more. Create dynamic pages easily.
Widget Logic
widget-logic
Widget Logic lets you control on which pages widgets appear using WP's conditional tags.
Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets
widget-options
0ddcemmihs4a843ekhaoofzosrunf4bl Widget Options gives you super powers to control your site’s sidebar widgets and all Gutenberg blocks on pages, posts …
User Profile Picture
metronet-profile-picture
Set a custom profile image (avatar) for a user using the standard WordPress media upload tool.
Team List Developer Profile
5 plugins · 13K total installs
How We Detect Team List
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-team-list/assets/dist/style-main.csswp-team-list/assets/dist/style-main.css?ver=HTML / DOM Fingerprints
wp-block-required-wp-team-list-team-list<!-- wp:required/wp-team-list-team-list -->data-wp-block="true"data-wp-block-name="required/wp-team-list-team-list"/wp-json/wp-team-list/v1/settings[team_list]