WPNakama – Team and multi-Client Collaboration, Editorial and Project Management Security & Risk Analysis

wordpress.org/plugins/wpnakama

Manage your teams, clients, tasks, Files, editorial, roadmap and deadlines. All-in-WordPress. For project management, task management, team collaborat …

10 active installs v0.6.6 PHP 7.4+ WP 6.2.0+ Updated Feb 14, 2026
client-managementeditorial-calendarkanbanproject-managementtask-management
94
A · Safe
CVEs total2
Unpatched0
Last CVEFeb 17, 2026
Safety Verdict

Is WPNakama – Team and multi-Client Collaboration, Editorial and Project Management Safe to Use in 2026?

Generally Safe

Score 94/100

WPNakama – Team and multi-Client Collaboration, Editorial and Project Management has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

2 known CVEsLast CVE: Feb 17, 2026Updated 3mo ago
Risk Assessment

The static analysis of wpnakama v0.6.6 indicates a generally good security posture with several positive aspects. The plugin employs prepared statements for all SQL queries and exhibits high output escaping rates, minimizing common web vulnerabilities like SQL injection and cross-site scripting. The absence of dangerous functions, file operations, and apparent unsanitized taint flows further strengthens this positive outlook. However, a notable concern arises from the vulnerability history, which reveals two high-severity vulnerabilities in the past, both related to SQL injection. While currently unpatched, the existence of these past issues warrants caution and suggests that the development team has, at times, struggled with robust SQL sanitization, even if recent versions appear to have addressed this in code. The presence of external HTTP requests, while not inherently a vulnerability, should be monitored for any potential for insecure data handling or unintended interactions with external services.

Key Concerns

  • 2 High Severity Vulnerabilities in History
  • External HTTP Requests Present
Vulnerabilities
2 published

WPNakama – Team and multi-Client Collaboration, Editorial and Project Management Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

High
2

2 total CVEs

CVE-2026-2495high · 7.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

WPNakama <= 0.6.5 - Unauthenticated SQL Injection via 'order' REST API Parameter

Feb 17, 2026 Patched in 0.6.6 (1d)
CVE-2025-14068high · 7.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

WPNakama <= 0.6.3 - Unauthenticated SQL Injection via 'order_by' Parameter

Dec 11, 2025 Patched in 0.6.4 (1d)
Version History

WPNakama – Team and multi-Client Collaboration, Editorial and Project Management Release Timeline

v0.6.51 CVE
v0.6.41 CVE
Code Analysis
Analyzed Apr 16, 2026

WPNakama – Team and multi-Client Collaboration, Editorial and Project Management Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
34 prepared
Unescaped Output
1
56 escaped
Nonce Checks
1
Capability Checks
6
File Operations
0
External Requests
5
Bundled Libraries
0

SQL Query Safety

100% prepared34 total queries

Output Escaping

98% escaped57 total outputs
Attack Surface

WPNakama – Team and multi-Client Collaboration, Editorial and Project Management Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 25
filteradmin_footer_textadmin/class-wpnakama-admin.php:62
actionload-plugins.phpadmin/class-wpnakama-admin.php:204
filterplugin_row_metaadmin/class-wpnakama-admin.php:214
filterrest_send_nocache_headersinc/class-wpnakama-api.php:67
actioninitinc/class-wpnakama-cpt.php:69
actionplugins_loadedinc/class-wpnakama.php:92
actionrest_api_initinc/class-wpnakama.php:182
actionplugins_loadedinc/class-wpnakama.php:2324
filterwpn_boards_cpt_argsinc/class-wpnakama.php:2487
actionadmin_menuinc/class-wpnakama.php:2555
actionadmin_initinc/class-wpnakama.php:2558
actionadmin_enqueue_scriptsinc/class-wpnakama.php:2561
actionenqueue_block_editor_assetsinc/class-wpnakama.php:2564
actioninitinc/class-wpnakama.php:2567
actionadmin_noticesinc/class-wpnakama.php:2570
actioninitinc/class-wpnakama.php:2660
filterquery_varsinc/class-wpnakama.php:2674
actiontemplate_redirectinc/class-wpnakama.php:2691
actionwp_enqueue_scriptsinc/class-wpnakama.php:2726
actioninitinc/class-wpnakama.php:2729
actionplugins_loadedinc/class-wpnakama.php:2754
filterplugins_apiinc/class-wpnakama.php:2784
filtersite_transient_update_pluginsinc/class-wpnakama.php:2787
filtertransient_update_pluginsinc/class-wpnakama.php:2788
actionupgrader_process_completeinc/class-wpnakama.php:2791
Maintenance & Trust

WPNakama – Team and multi-Client Collaboration, Editorial and Project Management Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 14, 2026
PHP min version7.4
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

WPNakama – Team and multi-Client Collaboration, Editorial and Project Management Developer Profile

qdonow

1 plugin · 10 total installs

96
trust score
Avg Security Score
94/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect WPNakama – Team and multi-Client Collaboration, Editorial and Project Management

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wpnakama/admin/css/admin.css/wp-content/plugins/wpnakama/admin/js/admin.js
Script Paths
/wp-content/plugins/wpnakama/admin/js/admin.js
Version Parameters
wpnakama/admin/css/admin.css?ver=wpnakama/admin/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
wpnakama-app-admin
Data Attributes
id="wpnakama-app-admin"
FAQ

Frequently Asked Questions about WPNakama – Team and multi-Client Collaboration, Editorial and Project Management