Add authors not users Security & Risk Analysis

wordpress.org/plugins/add-authors-not-users

This is a short description of what the plugin does. It's displayed in the WordPress admin area.

0 active installs v1.0.0 PHP + WP 3.0.1+ Updated Dec 15, 2017
commentsspam
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Add authors not users Safe to Use in 2026?

Generally Safe

Score 85/100

Add authors not users has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The 'add-authors-not-users' plugin v1.0.0 presents a mixed security profile. On the positive side, the static analysis reveals a very small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events exposed. Furthermore, all SQL queries utilize prepared statements, and there are no external HTTP requests or file operations detected. The presence of a nonce check and a capability check suggests an awareness of WordPress security best practices.

However, a significant concern arises from the output escaping analysis. With 100% of identified outputs not being properly escaped, this indicates a high potential for Cross-Site Scripting (XSS) vulnerabilities. If any user-supplied data is rendered directly on the frontend without proper sanitization, an attacker could inject malicious scripts. The lack of recorded vulnerabilities in its history is encouraging, but this does not negate the potential risks identified in the code itself. A robust security posture requires both a clean history and secure coding practices.

In conclusion, while the plugin boasts a limited attack surface and secure database interactions, the critical lack of output escaping poses a substantial risk that could be exploited for XSS attacks. The absence of past vulnerabilities is a good sign, but the identified coding deficiency needs immediate attention to ensure a secure user experience.

Key Concerns

  • Output not properly escaped
Vulnerabilities
None known

Add authors not users Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Add authors not users Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

Add authors not users Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

Add authors not users Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

Add authors not users Maintenance & Trust

Maintenance Signals

WordPress version tested3.4.2
Last updatedDec 15, 2017
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Add authors not users Developer Profile

heyyonatan

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Add authors not users

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/add-authors-not-users/css/add-authors-not-users-admin.css/wp-content/plugins/add-authors-not-users/js/add-authors-not-users-admin.js
Script Paths
/wp-content/plugins/add-authors-not-users/js/add-authors-not-users-admin.js
Version Parameters
add-authors-not-users-admin.css?ver=add-authors-not-users-admin.js?ver=

HTML / DOM Fingerprints

Data Attributes
aanu-review-metabox
FAQ

Frequently Asked Questions about Add authors not users