
Add authors not users Security & Risk Analysis
wordpress.org/plugins/add-authors-not-usersThis is a short description of what the plugin does. It's displayed in the WordPress admin area.
Is Add authors not users Safe to Use in 2026?
Generally Safe
Score 85/100Add authors not users has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'add-authors-not-users' plugin v1.0.0 presents a mixed security profile. On the positive side, the static analysis reveals a very small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events exposed. Furthermore, all SQL queries utilize prepared statements, and there are no external HTTP requests or file operations detected. The presence of a nonce check and a capability check suggests an awareness of WordPress security best practices.
However, a significant concern arises from the output escaping analysis. With 100% of identified outputs not being properly escaped, this indicates a high potential for Cross-Site Scripting (XSS) vulnerabilities. If any user-supplied data is rendered directly on the frontend without proper sanitization, an attacker could inject malicious scripts. The lack of recorded vulnerabilities in its history is encouraging, but this does not negate the potential risks identified in the code itself. A robust security posture requires both a clean history and secure coding practices.
In conclusion, while the plugin boasts a limited attack surface and secure database interactions, the critical lack of output escaping poses a substantial risk that could be exploited for XSS attacks. The absence of past vulnerabilities is a good sign, but the identified coding deficiency needs immediate attention to ensure a secure user experience.
Key Concerns
- Output not properly escaped
Add authors not users Security Vulnerabilities
Add authors not users Release Timeline
Add authors not users Code Analysis
Output Escaping
Add authors not users Attack Surface
Maintenance & Trust
Add authors not users Maintenance & Trust
Maintenance Signals
Community Trust
Add authors not users Alternatives
Akismet Anti-spam: Spam Protection
akismet
The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam solution for WordPress and WooCommerce.
Disable Comments – Remove Comments & Stop Spam [Multi-Site Support]
disable-comments
Allows administrators to globally disable comments on their site. Comments can be disabled according to post type. Multisite friendly.
Antispam Bee
antispam-bee
Sophisticated antispam plugin for effective daily comment and trackback spam-fighting. Built with data protection and privacy in mind.
Spam protection, Honeypot, Anti-Spam by CleanTalk
cleantalk-spam-protect
Blocks spam comments, fake users, contact form spam and more. No impact on SEO. Privacy focused. CAPTCHA free, premium Antispam plugin.
Captcha Code
captcha-code-authentication
GDPR compatible captcha anti-spam protection for login form, comments form, registration form & lost password form. Eliminate spam with captcha.
Add authors not users Developer Profile
1 plugin · 0 total installs
How We Detect Add authors not users
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/add-authors-not-users/css/add-authors-not-users-admin.css/wp-content/plugins/add-authors-not-users/js/add-authors-not-users-admin.js/wp-content/plugins/add-authors-not-users/js/add-authors-not-users-admin.jsadd-authors-not-users-admin.css?ver=add-authors-not-users-admin.js?ver=HTML / DOM Fingerprints
aanu-review-metabox