WP Team Members Security & Risk Analysis

wordpress.org/plugins/wp-team-members

This is full responsive cb team members plugin for wordpress websites with shortcode support. shortcode is [cb-members].

10 active installs v1.2 PHP + WP 3.0+ Updated Unknown
free-team-member-pluginteam-memberteam-members-pluginwordpress-team-member-pluginwp-team-member
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Team Members Safe to Use in 2026?

Generally Safe

Score 100/100

WP Team Members has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The wp-team-members plugin v1.2 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, file operations, and external HTTP requests is commendable. Furthermore, all SQL queries are properly prepared, and all outputs are correctly escaped, indicating good coding practices in these critical areas. The lack of any recorded vulnerabilities in its history, including critical or high severity ones, suggests a well-maintained and secure plugin over time.

However, the analysis does reveal some areas that warrant attention. The presence of a shortcode, while common, represents an entry point into the plugin's functionality. The complete absence of nonce checks and capability checks across all identified entry points (even though the attack surface is minimal with only one shortcode) is a significant concern. This lack of authentication and authorization checks means that any user, regardless of their role or privileges, could potentially interact with the shortcode, leading to unintended consequences or even exploitation if the shortcode's functionality is not inherently locked down.

While the attack surface is currently small, the lack of robust authorization mechanisms is a weakness. The plugin's history of zero vulnerabilities is a positive indicator, but it doesn't entirely mitigate the risk posed by missing security checks. The ideal approach would be to implement appropriate capability checks and nonce verification for the shortcode to ensure it's only used by authorized users and through legitimate requests.

Key Concerns

  • Missing capability checks on shortcode
  • Missing nonce checks on shortcode
Vulnerabilities
None known

WP Team Members Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP Team Members Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

WP Team Members Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[cb-members] index.php:107
WordPress Hooks 5
actionwp_enqueue_scriptsindex.php:24
actionafter_setup_themeindex.php:32
actioninitindex.php:38
filterenter_title_hereindex.php:123
actionadd_meta_boxesindex.php:146
Maintenance & Trust

WP Team Members Maintenance & Trust

Maintenance Signals

WordPress version tested5.0.25
Last updatedUnknown
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

WP Team Members Developer Profile

Md Abul Bashar

33 plugins · 1K total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Team Members

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about WP Team Members