WTG Tasks Manager Beta Security & Risk Analysis

wordpress.org/plugins/wtg-tasks-manager

Task management with a plan - this plugin will grow to meet the needs of online business managed within WordPress.

10 active installs v0.0.40 PHP + WP 3.8.0+ Updated Unknown
tasktask-managementtask-managertaskswtg
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WTG Tasks Manager Beta Safe to Use in 2026?

Generally Safe

Score 100/100

WTG Tasks Manager Beta has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "wtg-tasks-manager" plugin v0.0.40 exhibits a mixed security posture. On the positive side, the plugin demonstrates strong adherence to WordPress security best practices with a significant number of capability checks and the presence of nonce checks. The absence of known CVEs and a clear vulnerability history further contribute to its perceived safety. However, the static analysis reveals concerning areas that warrant attention.

The plugin's attack surface appears to be minimal or non-existent based on the provided entry points, which is a positive sign. Nevertheless, the presence of a dangerous function like `shell_exec` is a significant red flag. While the static analysis does not explicitly link this function to an exploitable path in the provided data, its mere presence introduces a potential avenue for remote code execution if misused or if input is not properly sanitized before being passed to it.

The significant number of SQL queries with a relatively low percentage of prepared statements (26%) suggests a potential risk of SQL injection vulnerabilities. Additionally, the low percentage of properly escaped output (11%) indicates a high likelihood of cross-site scripting (XSS) vulnerabilities, as user-supplied data is likely being rendered without sufficient sanitization. The taint analysis, while showing no critical or high severity flows, also indicates a concerning number of flows with unsanitized paths, reinforcing the potential for vulnerabilities in handling user input.

Key Concerns

  • Dangerous function shell_exec found
  • Low percentage of prepared statements in SQL queries
  • Low percentage of properly escaped output
  • Taint flows with unsanitized paths found
Vulnerabilities
None known

WTG Tasks Manager Beta Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WTG Tasks Manager Beta Code Analysis

Dangerous Functions
1
Raw SQL Queries
28
10 prepared
Unescaped Output
259
31 escaped
Nonce Checks
5
Capability Checks
24
File Operations
11
External Requests
1
Bundled Libraries
0

Dangerous Functions Found

shell_exec$output = shell_exec( 'mysql -V' );classes\class-phplibrary.php:458

SQL Query Safety

26% prepared38 total queries

Output Escaping

11% escaped290 total outputs
Data Flows
10 unsanitized

Data Flow Analysis

19 flows10 with unsanitized paths
csvimporttasksmultipleprojects (classes\class-requests.php:701)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WTG Tasks Manager Beta Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 24
actioninitclasses\class-install.php:45
actionswitch_blogclasses\class-install.php:46
actioninitclasses\class-install.php:50
actionswitch_blogclasses\class-install.php:51
filteradmin_footer_textclasses\class-ui.php:1597
actionadmin_print_footer_scriptsclasses\class-ui.php:1980
actionload-toplevel_page_wtgtasksmanagerclasses\class-wtgtasksmanager.php:880
filterwp_mail_content_typeclasses\class-wtgtasksmanager.php:1756
actioninitposttypes\flags.php:17
actionsave_postposttypes\flags.php:18
actionadd_meta_boxesposttypes\flags.php:19
actioninitposttypes\tasks.php:17
actionsave_postposttypes\tasks.php:18
actionadd_meta_boxesposttypes\tasks.php:19
filtermanage_edit-wtgtasks_columnsposttypes\tasks.php:158
actionmanage_wtgtasks_posts_custom_columnposttypes\tasks.php:159
actioninitposttypes\tasks.php:273
actioninitposttypes\tasks.php:285
actioninitposttypes\tasks.php:296
actioninitposttypes\tasks.php:307
actioninitposttypes\tasks.php:319
actioninitposttypes\tasks.php:331
actionadmin_footer-post.phpposttypes\tasks.php:420
actionplugins_loadedwtg-tasks-manager.php:80
Maintenance & Trust

WTG Tasks Manager Beta Maintenance & Trust

Maintenance Signals

WordPress version tested4.3.34
Last updatedUnknown
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

WTG Tasks Manager Beta Developer Profile

WebTechGlobal

4 plugins · 50 total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WTG Tasks Manager Beta

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wtg-tasks-manager/classes//wp-content/plugins/wtg-tasks-manager/classes/class-wpdb.php/wp-content/plugins/wtg-tasks-manager/classes/class-log.php/wp-content/plugins/wtg-tasks-manager/classes/class-configuration.php/wp-content/plugins/wtg-tasks-manager/classes/class-wtgtasksmanager.php/wp-content/plugins/wtg-tasks-manager/classes/class-wpdb.php/wp-content/plugins/wtg-tasks-manager/classes/class-phplibrary.php/wp-content/plugins/wtg-tasks-manager/classes/class-install.php+2 more
Version Parameters
wtg-tasks-manager/style.css?ver=wtg-tasks-manager/script.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about WTG Tasks Manager Beta