Author Box Reloaded Pack Security & Risk Analysis

wordpress.org/plugins/author-box-reloaded-pack

Adds the Author Box Reloaded External Contact plugins. REQUIRES Author Box Reloaded 2.0.3 or greater.

10 active installs v1.1.2 PHP + WP 2.8.0+ Updated May 28, 2014
authorextrathemeuseruser-profile-contacts
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Author Box Reloaded Pack Safe to Use in 2026?

Generally Safe

Score 85/100

Author Box Reloaded Pack has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

Based on the static analysis, the "author-box-reloaded-pack" plugin v1.1.2 presents a generally good security posture. The absence of identified AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the code demonstrates strong security practices by exclusively using prepared statements for SQL queries and ensuring all outputs are properly escaped. The lack of file operations and external HTTP requests also reduces potential vulnerabilities. The vulnerability history is clean, with no recorded CVEs, indicating a stable and likely well-maintained codebase. The primary concern identified in the static analysis is the use of the `create_function` dangerous function, which, while not directly exploitable without further context, is a deprecated and generally discouraged practice that can lead to security issues if not handled with extreme care. Despite this single flagged issue, the overall lack of other common vulnerability indicators and a clear vulnerability history points to a plugin that is likely secure for most use cases. However, the presence of `create_function` warrants a minor deduction as it represents a deviation from best practices.

Key Concerns

  • Use of dangerous function: create_function
Vulnerabilities
None known

Author Box Reloaded Pack Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Author Box Reloaded Pack Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

create_functionadd_action( 'admin_notices', create_function( '', "echo '$notice';" ) );author-box-reloaded-pack.php:87
Attack Surface

Author Box Reloaded Pack Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 15
actionadmin_noticesauthor-box-reloaded-pack.php:87
filterauthorbox_known_sitesbranchout.php:68
filterauthorbox_known_sitescrunchbase.php:68
filterauthorbox_known_sitesdrupalassociation.php:68
filterauthorbox_known_sitesfacebook.php:68
filterauthorbox_known_sitesgoogleplus.php:68
filterauthorbox_known_sitesidentica.php:68
filterauthorbox_known_siteslinkedin.php:68
filterauthorbox_known_sitesnetlog.php:68
filterauthorbox_known_sitesskypeme.php:68
filterauthorbox_known_sitestwitter.php:68
filterauthorbox_known_sitesvimeo.php:68
filterauthorbox_known_siteswordpress.php:68
filterauthorbox_known_sitesxing.php:68
filterauthorbox_known_sitesyoutube.php:68
Maintenance & Trust

Author Box Reloaded Pack Maintenance & Trust

Maintenance Signals

WordPress version tested3.9.40
Last updatedMay 28, 2014
PHP min version
Downloads7K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Author Box Reloaded Pack Developer Profile

Lopo Lencastre de Almeida

8 plugins · 150 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Author Box Reloaded Pack

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/author-box-reloaded-pack/css/styles.css/wp-content/plugins/author-box-reloaded-pack/css/additional-styles.css/wp-content/plugins/author-box-reloaded-pack/js/script.js
Script Paths
/wp-content/plugins/author-box-reloaded-pack/js/script.js
Version Parameters
author-box-reloaded-pack/css/styles.css?ver=author-box-reloaded-pack/css/additional-styles.css?ver=author-box-reloaded-pack/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
abr2pack-author-boxabr2pack-social-iconsabr2pack-contact-info
Data Attributes
data-abr2pack-id
JS Globals
abr2pack_ajax_object
FAQ

Frequently Asked Questions about Author Box Reloaded Pack