Author Filters Security & Risk Analysis

wordpress.org/plugins/author-filters

Author filters plugin integrates an author filter drop down to sort listing on post, page, custom post type in admin.

1K active installs v3.5.6 PHP + WP 4.9+ Updated Dec 21, 2020
authorcustom-post-typespagespostssorting
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Author Filters Safe to Use in 2026?

Generally Safe

Score 85/100

Author Filters has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The author-filters plugin v3.5.6 exhibits a strong security posture based on the provided static analysis. The absence of any detected dangerous functions, file operations, external HTTP requests, and the proper handling of SQL queries and output escaping are all positive indicators. Furthermore, the plugin demonstrates a secure approach to its limited attack surface by having zero AJAX handlers, REST API routes, shortcodes, or cron events. This suggests a very minimal exposure to potential threats.

The vulnerability history is also exceptionally clean, with no recorded CVEs across any severity levels. This, combined with the lack of any flagged taint flows, indicates that the plugin has either been rigorously developed with security in mind or has not yet been subjected to significant security scrutiny that would reveal vulnerabilities. The complete absence of nonce and capability checks is a notable absence, especially if the plugin were to expand its attack surface in the future. However, given the current zero attack surface, this is not an immediate risk.

In conclusion, the author-filters plugin v3.5.6 appears to be a highly secure plugin at present. Its strengths lie in its minimalist design and rigorous adherence to secure coding practices for the elements it does implement. The main area for potential future concern would be if new features are added without corresponding security checks, such as nonce and capability checks, to protect against potential unauthorized actions. However, based on the current data, the risk is minimal.

Key Concerns

  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

Author Filters Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Author Filters Release Timeline

v3.5.6Current
v3.5.0
v3.0.0
v2.0.0
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

Author Filters Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped2 total outputs
Attack Surface

Author Filters Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actioninitauthor-filters.php:42
actionpre_get_postsclass.authorfilter.php:28
actionrestrict_manage_postsclass.authorfilter.php:29
Maintenance & Trust

Author Filters Maintenance & Trust

Maintenance Signals

WordPress version tested5.6.17
Last updatedDec 21, 2020
PHP min version
Downloads16K

Community Trust

Rating100/100
Number of ratings4
Active installs1K
Developer Profile

Author Filters Developer Profile

Clarion Technologies

3 plugins · 2K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Author Filters

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/author-filters/css/style.css/wp-content/plugins/author-filters/js/author-filters.js
Script Paths
/wp-content/plugins/author-filters/js/author-filters.js
Version Parameters
author-filters/css/style.css?ver=author-filters/js/author-filters.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Author Filters