
Author Box Reloaded Security & Risk Analysis
wordpress.org/plugins/author-box-2Adds an author box to your blog. Fast and easy and fully configurable.
Is Author Box Reloaded Safe to Use in 2026?
Generally Safe
Score 85/100Author Box Reloaded has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "author-box-2" plugin v2.0.4.2 presents a mixed security posture. On the positive side, it exhibits strong practices regarding SQL queries, exclusively using prepared statements, and has no recorded vulnerability history, suggesting a generally well-maintained codebase in the past. The complete lack of external HTTP requests, file operations, and no recorded CVEs also contributes to a positive outlook.
However, the static analysis reveals significant concerns. The presence of two instances of the deprecated `create_function` is a major red flag, as this function is inherently insecure and prone to code injection vulnerabilities if user input is involved. Furthermore, a very low output escaping rate of only 33% indicates a high risk of cross-site scripting (XSS) vulnerabilities, especially if any of the unescaped outputs are ever exposed to user-controlled data. The absence of any nonce checks or capability checks, while not directly indicated as an attack vector in the provided data, suggests a lack of robust authorization and integrity checks at potential entry points, though the attack surface itself is reported as zero.
In conclusion, while the plugin benefits from good SQL practices and a clean vulnerability history, the use of `create_function` and the poor output escaping are critical security weaknesses that demand immediate attention. These issues create exploitable pathways for attackers, particularly for XSS and potentially remote code execution.
Key Concerns
- Dangerous function used (create_function)
- Low output escaping rate (33%)
- Missing nonce checks
- Missing capability checks
Author Box Reloaded Security Vulnerabilities
Author Box Reloaded Code Analysis
Dangerous Functions Found
Output Escaping
Author Box Reloaded Attack Surface
WordPress Hooks 6
Maintenance & Trust
Author Box Reloaded Maintenance & Trust
Maintenance Signals
Community Trust
Author Box Reloaded Alternatives
Author Box Reloaded Pack
author-box-reloaded-pack
Adds the Author Box Reloaded External Contact plugins. REQUIRES Author Box Reloaded 2.0.3 or greater.
WP Themes & Plugins Stats
wp-themes-plugins-stats
The WP Themes & Plugins Stats plugin automatically fetch theme and plugin stats ( name, active installs, 5-star ratings, etc.
One Click Demo Import
one-click-demo-import
Import your demo content, widgets and theme settings with one click. Theme authors! Enable simple theme demo import for your users.
Redux Framework
redux-framework
Redux is a simple, truly extensible, and fully responsive options framework for WordPress themes and plugins. It ships with an integrated demo.
Simple Custom CSS and JS
custom-css-js
Easily add Custom CSS or JS to your website with an awesome editor.
Author Box Reloaded Developer Profile
8 plugins · 150 total installs
How We Detect Author Box Reloaded
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/author-box-2/authorbox-admin.css/wp-content/plugins/author-box-2/authorbox-ltr.css/wp-content/plugins/author-box-2/authorbox-rtl.cssauthorbox-admin-css?ver=authorbox-reloaded-css?ver=HTML / DOM Fingerprints
author-box-2Author Box CSS pesonalized by blog authorid="ab2_auto_insert"id="ab2_photo_align"id="ab2_personal_css"name="ab2[auto_insert]"name="ab2[photo_align]"name="ab2[personal_css]"[author-box-2]