
Author Box Plus Security & Risk Analysis
wordpress.org/plugins/author-box-plusAuthor Box Plus allows blog owners to manage authors and their profiles.
Is Author Box Plus Safe to Use in 2026?
Generally Safe
Score 85/100Author Box Plus has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The author-box-plus plugin version 1.0.3 exhibits a generally strong security posture based on the provided static analysis. The absence of identified AJAX handlers, REST API routes, shortcodes, and cron events with unprotected entry points is a significant strength, indicating a minimal attack surface. Furthermore, the lack of dangerous functions, file operations, and external HTTP requests further bolsters its security. The presence of capability checks, while limited, suggests some consideration for access control. However, there are notable areas for improvement. The low percentage of properly escaped output (3%) is a significant concern, potentially leading to cross-site scripting (XSS) vulnerabilities. Additionally, 40% of SQL queries are not using prepared statements, which could open the door to SQL injection attacks. The absence of any recorded vulnerabilities in its history is positive, suggesting a history of secure development or timely patching, but it doesn't negate the risks identified in the static analysis. Overall, while the plugin has a small attack surface and no history of publicly disclosed vulnerabilities, the identified issues with output escaping and SQL query sanitization present tangible risks that should be addressed.
Key Concerns
- Low percentage of properly escaped output
- SQL queries not using prepared statements
- No nonce checks
Author Box Plus Security Vulnerabilities
Author Box Plus Code Analysis
SQL Query Safety
Output Escaping
Author Box Plus Attack Surface
WordPress Hooks 14
Maintenance & Trust
Author Box Plus Maintenance & Trust
Maintenance Signals
Community Trust
Author Box Plus Alternatives
Pure Metafields
pure-metafields
Pure Metafields is very light weight plugin tused to create custom metabox for any post type like page, post and your custom post type support it.
WP Author, Date and Meta Remover
wp-author-date-and-meta-remover
Don't need the post date and author meta data on your pages? Install WP Author, Date and Meta Remover and its gone. It's that easy!
Author Filters
author-filters
Author filters plugin integrates an author filter drop down to sort listing on post, page, custom post type in admin.
WP About Author
wp-about-author
Easily display customizable author bios below your posts
Widget Pack
ts-widget-pack
Widget Pack is a WordPress plugin that enables essential, yet powerful features for your website.
Author Box Plus Developer Profile
6 plugins · 370 total installs
How We Detect Author Box Plus
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/author-box-plus/assets/css/abp.cssauthor-box-plus/assets/css/abp.css?ver=HTML / DOM Fingerprints
abp-author-bioabp-author-socialabp-author-avatarabp-author-nameabp-author-titleabp-author-descriptiondata-abp-author-id