
About Author Box Security & Risk Analysis
wordpress.org/plugins/about-author-boxDisplay information about the post author automatically or using a shortcode.
Is About Author Box Safe to Use in 2026?
Generally Safe
Score 85/100About Author Box has a strong security track record. Known vulnerabilities have been patched promptly.
The 'about-author-box' v1.0.3 plugin exhibits a generally good security posture based on the static analysis. The plugin demonstrates strong adherence to secure coding practices by avoiding dangerous functions, ensuring all SQL queries use prepared statements, and properly escaping the vast majority (98%) of its output. The limited attack surface, with only one shortcode and no unprotected entry points, further contributes to its secure design. The absence of taint analysis findings and file operations also suggests a low risk of direct code injection or manipulation vulnerabilities.
However, a significant concern is the plugin's vulnerability history. It has a known medium severity CVE related to Cross-Site Scripting (XSS), which, while currently patched according to the data, indicates a past weakness in input sanitization or output escaping for certain scenarios. The fact that this vulnerability occurred relatively recently (2021) warrants attention, as it suggests that past security assessments might have missed certain input vectors. The absence of nonce checks, while not directly flagged as an issue in this static analysis due to the limited attack surface and entry points, is a standard security control that is missing and could become a risk if the attack surface expands or new entry points are introduced in future versions without proper checks.
In conclusion, while the current version of the 'about-author-box' plugin appears to be in a good state regarding static code analysis, the past XSS vulnerability serves as a reminder of its potential weaknesses. The lack of nonce checks is a minor concern that, combined with the historical vulnerability, suggests a need for ongoing vigilance and potentially more comprehensive security testing for this plugin.
Key Concerns
- Past medium severity CVE (XSS)
- Missing nonce checks
About Author Box Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
About Author Box < 1.0.2 - Cross-Site Scripting
About Author Box Code Analysis
Output Escaping
About Author Box Attack Surface
Shortcodes 1
WordPress Hooks 14
Maintenance & Trust
About Author Box Maintenance & Trust
Maintenance Signals
Community Trust
About Author Box Alternatives
Molongui Authorship – Author Boxes, Guest Authors & Co-Authors for WordPress
molongui-authorship
All-in-One Authorship Solution: Seamless Author Box, Guest Authors, and Co-Authors to enhance your site's authority, credibility, engagement, and SEO.
Starbox – the Author Box for Humans
starbox
Starbox is the Author Box for Humans. Professional Themes to choose from, HTML5, Social Media Profiles, Google Authorship
Authorsy – Author Box, Multiple Authors, Guest Authors & Post Rating
authorsy
Authorsy is a powerful WordPress author box plugin. Add customizable author profiles, multiple authors, guest authors, bios, social links, and post ra …
Kantbtrue about me
kantbtrue-about-me
An elegant about me widget and profile widget for blogs. With this plugin you can add title, description with links, profile image and social links.
Author Box by Nocksoft
author-box-by-nocksoft
Adds a modern author info box at the end of your posts and implements local avatars as an alternative to Gravatar.
About Author Box Developer Profile
9 plugins · 238K total installs
How We Detect About Author Box
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/about-author-box/css/about-author-box.cssabout-author-box/css/about-author-box.css?ver=HTML / DOM Fingerprints
about-author-boxabout-author-box-border-about-author-box-sidebarabout-author-box-sidebar-position-about-author-box-avatarabout-author-box-avatar-style-about-author-box-mainabout-author-box-info+12 moreabout_author_box_twitterabout_author_box_facebookabout_author_box_instagramabout_author_box_behanceabout_author_box_dribbbleabout_author_box_vine+2 more[about_author_box]display_shortcode