
Author Bio Shortcode Security & Risk Analysis
wordpress.org/plugins/author-bio-shortcodeProvides the [author_bio] shortcode for embedding the bio of an author anywhere in the post/page content.
Is Author Bio Shortcode Safe to Use in 2026?
Use With Caution
Score 64/100Author Bio Shortcode has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "author-bio-shortcode" plugin version 2.5.3 exhibits a mixed security posture. On the positive side, the static analysis reveals strong adherence to secure coding practices, with no dangerous functions identified, all SQL queries using prepared statements, and 100% of outputs properly escaped. There are no file operations or external HTTP requests, contributing to a reduced attack surface. However, the plugin completely lacks nonce checks and capability checks, which is a significant concern as these are fundamental security mechanisms for protecting against unauthorized actions and cross-site request forgery (CSRF).
The vulnerability history is a major red flag. The plugin has a known CVE associated with it, and critically, this vulnerability is currently unpatched. The common vulnerability type being Cross-site Scripting (XSS) further emphasizes the risk. While the static analysis didn't directly uncover XSS vulnerabilities in this specific version's code review, the historical data strongly suggests that past versions were susceptible, and the lack of any indication of how this was addressed in 2.5.3, combined with the unpatched status, points to a lingering or unresolved security flaw.
In conclusion, while the codebase itself shows good general practices in areas like SQL and output escaping, the absence of fundamental security checks like nonces and capability checks, coupled with a known, unpatched medium-severity vulnerability (XSS), creates a significant risk. Users should be extremely cautious when deploying this plugin.
Key Concerns
- Unpatched CVE
- Missing nonce checks
- Missing capability checks
Author Bio Shortcode Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Author Bio Shortcode <= 2.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
Author Bio Shortcode Code Analysis
Output Escaping
Author Bio Shortcode Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
Author Bio Shortcode Maintenance & Trust
Maintenance Signals
Community Trust
Author Bio Shortcode Alternatives
Individual Multisite Author
individual-multisite-author
This plugin enables individual author descriptions for each single blog in a multisite network.
Simple Author Bio
simple-author-bio
Plugin that shows the author's biography in the foot of the posts.
Author Box by Nocksoft
author-box-by-nocksoft
Adds a modern author info box at the end of your posts and implements local avatars as an alternative to Gravatar.
WP Author Profile Widget
wp-author-profile-widget
Add WP Author Profile Widget with easy way.
Short Bio Widget
short-bio-widget
Its a widget that collects your short biography and show into wordpress sidebar area. User can add gravatar, name, short personal details, all common …
Author Bio Shortcode Developer Profile
7 plugins · 430 total installs
How We Detect Author Bio Shortcode
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/author-bio-shortcode/css/author-bio-shortcode.css/wp-content/plugins/author-bio-shortcode/js/author-bio-shortcode.js/wp-content/plugins/author-bio-shortcode/js/author-bio-shortcode.jsauthor-bio-shortcode/css/author-bio-shortcode.css?ver=author-bio-shortcode/js/author-bio-shortcode.js?ver=HTML / DOM Fingerprints
author_bio_shortcodeauthor_bio_shortcodenameavatarbiodata-iddata-usernamedata-emaildata-avatardata-avatar-sizedata-name+12 more<div class="author_bio_shortcode"><h3 class="name"><div class="avatar"><div class="bio">