
WP Custom Author Image Security & Risk Analysis
wordpress.org/plugins/author-imageLets you easily add WP Custom Author Images on your site.
Is WP Custom Author Image Safe to Use in 2026?
Generally Safe
Score 85/100WP Custom Author Image has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The author-image plugin v1.0 exhibits a mixed security posture. On the positive side, it has a very small attack surface, with only one shortcode identified as an entry point and no unprotected handlers for AJAX or REST API requests. The absence of known CVEs in its history is also a strong indicator of past security diligence. However, the code analysis reveals significant areas of concern. Notably, 100% of its SQL queries are not using prepared statements, which presents a high risk of SQL injection vulnerabilities. Furthermore, only 44% of output is properly escaped, leaving potential for cross-site scripting (XSS) vulnerabilities. The lack of nonce checks and only one capability check across the plugin's operations suggest that authentication and authorization might not be consistently enforced, especially if the shortcode interacts with sensitive data or functions.
Key Concerns
- SQL queries not using prepared statements
- Low percentage of properly escaped output
- No nonce checks
- Minimal capability checks
WP Custom Author Image Security Vulnerabilities
WP Custom Author Image Code Analysis
SQL Query Safety
Output Escaping
WP Custom Author Image Attack Surface
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
WP Custom Author Image Maintenance & Trust
Maintenance Signals
Community Trust
WP Custom Author Image Alternatives
Mindutopia User Thumbnails
mindutopia-user-thumbnails
This plugin gives you the ability to add user thumbnails to your WordPress users much like featured images on posts, the images replace the gravatars.
Edit Author Slug
edit-author-slug
Allows an admin (or capable user) to edit the author slug of a user, and change the author base.
Simple Local Avatars
simple-local-avatars
Adds an avatar upload field to user profiles. Generates requested sizes on demand just like Gravatar!
WP Meta and Date Remover
wp-meta-and-date-remover
Remove meta author and date information from posts and pages. Hide from Humans and Search engines.SEO friendly and most advance plugin.
Simple Author Box
simple-author-box
Add a responsive author box or guest author box with social icons to any post. Great author box for any site!
WP Custom Author Image Developer Profile
2 plugins · 110 total installs
How We Detect WP Custom Author Image
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-custom-author-image/css/style.css/wp-content/plugins/wp-custom-author-image/js/script.js/wp-content/plugins/wp-custom-author-image/js/script.jswp-custom-author-image/css/style.css?ver=wp-custom-author-image/js/script.js?ver=HTML / DOM Fingerprints
wp_custom_author_image<!-- START WP CUSTOM AUTHOR IMAGE CODE --><!-- END WP CUSTOM AUTHOR IMAGE CODE -->data-author-iddata-image-sizewp_custom_author_image_settings[wp_custom_author_image][wp_custom_author_image title="" bio="" link="" always="" size="" author_id=""]