
Author Box Reloaded Security & Risk Analysis
wordpress.org/plugins/author-box-2Adds an author box to your blog. Fast and easy and fully configurable.
Is Author Box Reloaded Safe to Use in 2026?
Generally Safe
Score 85/100Author Box Reloaded has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "author-box-2" plugin v2.0.4.2 presents a mixed security posture. On the positive side, it exhibits strong practices regarding SQL queries, exclusively using prepared statements, and has no recorded vulnerability history, suggesting a generally well-maintained codebase in the past. The complete lack of external HTTP requests, file operations, and no recorded CVEs also contributes to a positive outlook.
However, the static analysis reveals significant concerns. The presence of two instances of the deprecated `create_function` is a major red flag, as this function is inherently insecure and prone to code injection vulnerabilities if user input is involved. Furthermore, a very low output escaping rate of only 33% indicates a high risk of cross-site scripting (XSS) vulnerabilities, especially if any of the unescaped outputs are ever exposed to user-controlled data. The absence of any nonce checks or capability checks, while not directly indicated as an attack vector in the provided data, suggests a lack of robust authorization and integrity checks at potential entry points, though the attack surface itself is reported as zero.
In conclusion, while the plugin benefits from good SQL practices and a clean vulnerability history, the use of `create_function` and the poor output escaping are critical security weaknesses that demand immediate attention. These issues create exploitable pathways for attackers, particularly for XSS and potentially remote code execution.
Key Concerns
- Dangerous function used (create_function)
- Low output escaping rate (33%)
- Missing nonce checks
- Missing capability checks
Author Box Reloaded Security Vulnerabilities
Author Box Reloaded Release Timeline
Author Box Reloaded Code Analysis
Dangerous Functions Found
Output Escaping
Author Box Reloaded Attack Surface
WordPress Hooks 6
Maintenance & Trust
Author Box Reloaded Maintenance & Trust
Maintenance Signals
Community Trust
Author Box Reloaded Alternatives
Assign Staff as Author for Total
assign-staff-as-author-for-total
Assign staff members as the "author" for any page or post to be displayed in the post meta or author bio.
Author Box Reloaded Pack
author-box-reloaded-pack
Adds the Author Box Reloaded External Contact plugins. REQUIRES Author Box Reloaded 2.0.3 or greater.
WP Themes & Plugins Stats
wp-themes-plugins-stats
The WP Themes & Plugins Stats plugin automatically fetch theme and plugin stats ( name, active installs, 5-star ratings, etc.
WPRS Data Transporter
wprs-data-transporter
Simply transfer your inputs Schema markups for reviews and star ratings data from one theme/plugin to another.
API info for Plugins & Themes from WP.ORG
api-info-themes-plugins-wp-org
[ ✅ 𝐒𝐄𝐂𝐔𝐑𝐄 𝐏𝐋𝐔𝐆𝐈𝐍𝐒 b𝓎 𝒫𝓊𝓋𝑜𝓍 ] Show Plugins & Themes information on your site, from WP.ORG API
Author Box Reloaded Developer Profile
8 plugins · 150 total installs
How We Detect Author Box Reloaded
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/author-box-2/authorbox-admin.css/wp-content/plugins/author-box-2/authorbox-ltr.css/wp-content/plugins/author-box-2/authorbox-rtl.cssauthorbox-admin-css?ver=authorbox-reloaded-css?ver=HTML / DOM Fingerprints
author-box-2Author Box CSS pesonalized by blog authorid="ab2_auto_insert"id="ab2_photo_align"id="ab2_personal_css"name="ab2[auto_insert]"name="ab2[photo_align]"name="ab2[personal_css]"[author-box-2]