About the Author Advanced Security & Risk Analysis

wordpress.org/plugins/about-the-author-advanced

This plugin creates a sidebar widget which displays the post/page author's information.

50 active installs v0.2.3 PHP + WP 3.0+ Updated Sep 14, 2012
about-the-authorauthorauthor-bioauthor-bio-widgetauthor-info
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is About the Author Advanced Safe to Use in 2026?

Generally Safe

Score 85/100

About the Author Advanced has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

The "about-the-author-advanced" plugin v0.2.3 exhibits a mixed security posture. While the static analysis shows no exposed attack surface through AJAX, REST API, shortcodes, or cron events, and all SQL queries utilize prepared statements, there are significant concerns. A critical red flag is the presence of the `create_function` dangerous function, which can lead to serious security vulnerabilities if misused. Furthermore, the complete lack of output escaping for all 38 identified outputs is a severe weakness, opening the door to cross-site scripting (XSS) attacks. The absence of nonce checks and capability checks on any potential entry points is also a considerable risk, as it suggests a lack of proper authorization and integrity checks.

Key Concerns

  • Dangerous function detected (create_function)
  • No output escaping found
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

About the Author Advanced Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

About the Author Advanced Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
38
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

create_functionadd_action('plugins_loaded', create_function('','new Acip_Edit_Options();'));classes\edit-options.php:234

Output Escaping

0% escaped38 total outputs
Attack Surface

About the Author Advanced Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_initabout-the-author-advanced.php:79
actionadmin_initabout-the-author-advanced.php:89
filteruser_contactmethodsabout-the-author-advanced.php:122
filterplugin_row_metaabout-the-author-advanced.php:158
actionwidgets_initabout-the-author-advanced.php:178
actionadmin_menuclasses\edit-options.php:7
filteruser_contactmethodsclasses\edit-options.php:8
actionplugins_loadedclasses\edit-options.php:234
Maintenance & Trust

About the Author Advanced Maintenance & Trust

Maintenance Signals

WordPress version tested3.4.2
Last updatedSep 14, 2012
PHP min version
Downloads14K

Community Trust

Rating100/100
Number of ratings1
Active installs50
Developer Profile

About the Author Advanced Developer Profile

Dan

2 plugins · 80 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect About the Author Advanced

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/about-the-author-advanced/css/ataa.css
Version Parameters
about-the-author-advanced/css/ataa.css?t=

HTML / DOM Fingerprints

CSS Classes
Ataa_Widget
Data Attributes
data-ataa-profile-picture
FAQ

Frequently Asked Questions about About the Author Advanced