
Additional Authors Security & Risk Analysis
wordpress.org/plugins/additional-authorsLet's you add more than one author to your posts.
Is Additional Authors Safe to Use in 2026?
Generally Safe
Score 85/100Additional Authors has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "additional-authors" plugin version 1.3.5 exhibits a mixed security posture. On the positive side, the plugin shows good practices by avoiding dangerous functions, file operations, and external HTTP requests. The majority of its SQL queries utilize prepared statements, and most output is properly escaped. Furthermore, the absence of known vulnerabilities (CVEs) and taint analysis findings suggests a generally well-maintained codebase.
However, significant concerns arise from the attack surface. The plugin exposes two AJAX handlers, both of which lack authentication checks. This is a critical security weakness, as it allows any user, including unauthenticated ones, to trigger these handlers, potentially leading to unauthorized actions or information disclosure. While there's a nonce check and capability checks present, their effectiveness is diminished by the lack of overall authentication on these entry points.
In conclusion, while the plugin demonstrates strengths in areas like SQL handling and output sanitization, the unprotected AJAX endpoints represent a substantial risk. The vulnerability history is clean, which is a positive indicator, but the present code analysis reveals a clear and actionable security gap that should be addressed immediately.
Key Concerns
- AJAX handlers without authentication checks
- Large attack surface without auth
Additional Authors Security Vulnerabilities
Additional Authors Code Analysis
SQL Query Safety
Output Escaping
Additional Authors Attack Surface
AJAX Handlers 2
WordPress Hooks 18
Maintenance & Trust
Additional Authors Maintenance & Trust
Maintenance Signals
Community Trust
Additional Authors Alternatives
Edit Author Slug
edit-author-slug
Allows an admin (or capable user) to edit the author slug of a user, and change the author base.
WP Meta and Date Remover
wp-meta-and-date-remover
Remove meta author and date information from posts and pages. Hide from Humans and Search engines.SEO friendly and most advance plugin.
Simple Author Box
simple-author-box
Add a responsive author box or guest author box with social icons to any post. Great author box for any site!
Co-Authors Plus
co-authors-plus
Assign multiple bylines to posts, pages, and custom post types with a search-as-you-type input box.
Hide/Remove Metadata
hide-metadata
Hide/Remove Metadata is a free WordPress plugin that helps you hide author and published date either by CSS or PHP from your website effortlessly.
Additional Authors Developer Profile
22 plugins · 2K total installs
How We Detect Additional Authors
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/additional-authors/dist/users-table.js/wp-content/plugins/additional-authors/dist/additional-authors-meta-box.css/wp-content/plugins/additional-authors/dist/additional-authors-meta-box.js/wp-content/plugins/additional-authors/dist/additional-authors.css/wp-content/plugins/additional-authors/dist/additional-authors.js/wp-content/plugins/additional-authors/dist/users-table.js/wp-content/plugins/additional-authors/dist/additional-authors-meta-box.js/wp-content/plugins/additional-authors/dist/additional-authors.jsadditional-authors/dist/users-table.asset.phpadditional-authors/dist/additional-authors-meta-box.asset.phpadditional-authors/dist/additional-authors.asset.phpHTML / DOM Fingerprints
data-additional-authors-searchAdditionalAuthors