
WP To Do Security & Risk Analysis
wordpress.org/plugins/wp-todoWP-Todo: Smart To-Do List & Task Management Plugin for WordPress
Is WP To Do Safe to Use in 2026?
Generally Safe
Score 97/100WP To Do has a strong security track record. Known vulnerabilities have been patched promptly.
The wp-todo plugin version 2.1.7 exhibits a mixed security posture. While the code demonstrates strong adherence to secure coding practices, such as using prepared statements for all SQL queries and a high percentage of properly escaped output, significant concerns arise from its attack surface. A total of four AJAX handlers are present, and alarmingly, all of them lack authentication checks. This creates a considerable risk of unauthorized actions being performed on the site. The taint analysis shows no critical or high severity unsanitized paths, which is positive, but the lack of authentication on AJAX endpoints bypasses any potential security checks that might otherwise be present.
Key Concerns
- 4 AJAX handlers without auth checks
- 7 medium severity CVEs, 0 currently unpatched
WP To Do Security Vulnerabilities
CVEs by Year
Severity Breakdown
7 total CVEs
WP To Do <= 1.3.0 - Authenticated (Admin+) Stored Cross-Site Scripting via Task Comments
WP To Do <= 1.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
WP To Do <= 1.3.0 - Cross-Site Request Forgery via wptodo_addcomment
WP To Do <= 1.3.0 - Cross-Site Request Forgery via wptodo_manage()
WP To Do <= 1.3.0 - Cross-Site Request Forgery via wptodo_settings
WP To Do <= 1.3.0 - Authenticated (Admin+) Stored Cross-Site Scripting via Settings
WP To Do <= 1.2.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
WP To Do Code Analysis
Output Escaping
Data Flow Analysis
WP To Do Attack Surface
AJAX Handlers 4
WordPress Hooks 21
Maintenance & Trust
WP To Do Maintenance & Trust
Maintenance Signals
Community Trust
WP To Do Alternatives
Zephyr Project Manager
zephyr-project-manager
Zephyr Project Manager is a modern, easy to use sophisticated project manager for WordPress.
Todo Block
todo-block
Adds ToDo list block that shows checkboxes on frontend and backend of your site.
Eonet Project Manager
eonet-project-manager
Make your site a complete project management tool: create projects, set permissions and assign tasks your users.
Easy Project
iprojectweb
Easy to use yet powerful project management tool
To Do List Member
todo-lists-for-membership-sites
To Do List Member adds todolists and tasks using custom taxonomy and post type to your blog.
WP To Do Developer Profile
1 plugin · 100 total installs
How We Detect WP To Do
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-todo/assets/js/wptodo-admin.js/wp-content/plugins/wp-todo/assets/css/style.css/wp-content/plugins/wp-todo/assets/js/FullCalendar.min.js/wp-content/plugins/wp-todo/assets/js/Sortable.min.js/wp-content/plugins/wp-todo/assets/js/wptodo-dashboard.js/wp-content/plugins/wp-todo/assets/js/wptodo-admin.js/wp-content/plugins/wp-todo/assets/js/FullCalendar.min.js/wp-content/plugins/wp-todo/assets/js/Sortable.min.js/wp-content/plugins/wp-todo/assets/js/wptodo-dashboard.jswp-todo/style.css?ver=wptodo-admin-js?ver=style?ver=fullcalendar-js?ver=sortable-js?ver=wptodo-dashboard-js?ver=HTML / DOM Fingerprints
wptodo-clickablewptodo-modalwptodo-commentdata-post-idwptodo_ajaxwptodo_dashboard/wp-json/wp-todo/v1/tasks