Author Avatars List/Block Security & Risk Analysis
wordpress.org/plugins/author-avatarsDisplay lists of user avatars using widgets or shortcodes. With Gutenberg support.
Is Author Avatars List/Block Safe to Use in 2026?
Generally Safe
Score 98/100Author Avatars List/Block has a strong security track record. Known vulnerabilities have been patched promptly.
The author-avatars v2.1.25 plugin exhibits a generally good security posture based on the static analysis. The plugin demonstrates a commitment to secure coding practices by utilizing prepared statements for all SQL queries and properly escaping the vast majority of its output. The absence of dangerous functions, file operations, and external HTTP requests further strengthens its security. Crucially, all identified entry points (AJAX handlers) have nonce checks, a vital layer of protection against CSRF attacks.
Key Concerns
- No capability checks on AJAX handlers
- Bundled TinyMCE library
- Medium severity CVEs in history
Author Avatars List/Block Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Author Avatars List/Block <= 2.1.23 - Authenticated (Contributor+) Stored Cross-Site Scripting
Author Avatars List/Block <= 2.1.21 - Authenticated (Subscriber+) Stored Cross-Site Scripting
Author Avatars List/Block <= 2.1.17 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Author Avatars List/Block Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Author Avatars List/Block Attack Surface
AJAX Handlers 2
WordPress Hooks 5
Maintenance & Trust
Author Avatars List/Block Maintenance & Trust
Maintenance Signals
Community Trust
Author Avatars List/Block Alternatives
User Avatar – Reloaded
user-avatar-reloaded
Use any image from your WordPress Media Library as a custom user avatar or user profile picture. Add your own Default Avatar.
WP Custom Author Image
author-image
Lets you easily add WP Custom Author Images on your site.
User Profile Picture
metronet-profile-picture
Set a custom profile image (avatar) for a user using the standard WordPress media upload tool.
Meks Smart Author Widget
meks-smart-author-widget
Easily display your author/user profile info inside WordPress widget.
Ultimate Post List
ultimate-post-list
Make up custom-tailored preview lists of the contents easily and place them in widget areas and post contents.
Author Avatars List/Block Developer Profile
6 plugins · 5K total installs
How We Detect Author Avatars List/Block
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/author-avatars/build/show-avatar/style-block.css/wp-content/plugins/author-avatars/build/show-avatar/block.js/wp-content/plugins/author-avatars/build/show-avatar/block.css/wp-content/plugins/author-avatars/build/show-avatar/block.jsHTML / DOM Fingerprints
shortcode-author-avatarsdata-aa-actionauthorAvatars<div class="shortcode-author-avatars">