MM Author Box Security & Risk Analysis

wordpress.org/plugins/about-post-author

Display a box About Post Author with author name, avatar and description after each blog post.

40 active installs v1.4.1 PHP 7.2+ WP 5.2+ Updated Feb 4, 2026
about-author-boxauthor-boxauthor-meta-boxsimple-author-boxsmart-author-box
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is MM Author Box Safe to Use in 2026?

Generally Safe

Score 100/100

MM Author Box has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The 'about-post-author' plugin, version 1.4.1, demonstrates a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, raw SQL queries, file operations, external HTTP requests, or unsanitized taint flows is highly commendable. Furthermore, the 100% output escaping and the presence of at least one capability check indicate good development practices for protecting against common web vulnerabilities. The plugin's vulnerability history being completely clear, with no recorded CVEs, further bolsters its security reputation.

However, the analysis does reveal a potential area for improvement. The complete lack of nonce checks across all entry points, combined with zero unprotected AJAX handlers and zero unprotected REST API routes, might suggest a very limited attack surface but also a potential oversight in a crucial security mechanism. While the current version might not suffer from issues due to its minimal entry points, future additions or complex integrations could inadvertently expose vulnerabilities if nonce validation is not a standard practice. Overall, this plugin appears robust and secure for its current functionality, with the primary caution revolving around the consistent application of nonces for enhanced security, especially as the plugin evolves.

Key Concerns

  • No nonce checks implemented
Vulnerabilities
None known

MM Author Box Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

MM Author Box Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
34 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped34 total outputs
Attack Surface

MM Author Box Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
filterthe_contentabout-post-author.php:80
actionwp_enqueue_scriptsabout-post-author.php:86
actionadmin_enqueue_scriptsabout-post-author.php:93
actionwp_enqueue_scriptsabout-post-author.php:101
actionadmin_menuabout-post-author.php:115
actionadmin_initabout-post-author.php:211
actionwp_headabout-post-author.php:228
actionshow_user_profileabout-post-author.php:263
actionedit_user_profileabout-post-author.php:264
actionpersonal_options_updateabout-post-author.php:277
actionedit_user_profile_updateabout-post-author.php:278
Maintenance & Trust

MM Author Box Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 4, 2026
PHP min version7.2
Downloads3K

Community Trust

Rating20/100
Number of ratings2
Active installs40
Developer Profile

MM Author Box Developer Profile

MM Plugin

3 plugins · 150 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect MM Author Box

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/about-post-author/assets/images/facebook.png/wp-content/plugins/about-post-author/assets/images/twitter.png/wp-content/plugins/about-post-author/assets/images/linkedin.png/wp-content/plugins/about-post-author/assets/images/instagram.png
Script Paths
/wp-content/plugins/about-post-author/assets/js/admin-script.js
Version Parameters
about-post-author/assets/css/author-box.css?ver=about-post-author/assets/css/admin-styles.css?ver=about-post-author/assets/js/admin-script.js?ver=

HTML / DOM Fingerprints

CSS Classes
about-post-author-sectionauthor-avatarauthor-detailssocial-media-iconssocial-iconabout-post-author-settings-wrapabout-post-author-tabsabout-post-author-tab-content
Data Attributes
id="about-post-author-background-color"name="about-post-author-background-color"id="about-post-author-text-color"name="about-post-author-text-color"id="about-post-author-font-size"name="about-post-author-font-size"+4 more
FAQ

Frequently Asked Questions about MM Author Box