
Author List Security & Risk Analysis
wordpress.org/plugins/author-listDisplay the list of authors with gravatar image and show the total number of post count on hover
Is Author List Safe to Use in 2026?
Generally Safe
Score 85/100Author List has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "author-list" plugin version 2.2.1 exhibits a generally good security posture based on the provided static analysis. The absence of identified dangerous functions, SQL injection vulnerabilities (all queries use prepared statements), file operations, and external HTTP requests are positive indicators. Furthermore, the plugin has no known historical CVEs, suggesting a stable and potentially well-maintained security record.
However, several areas raise concerns. The very low percentage of properly escaped output (8%) presents a significant risk of cross-site scripting (XSS) vulnerabilities. While the attack surface is reported as zero, this is counterbalanced by a complete lack of capability checks and nonce checks. This means that any functionality, if it were to exist and be discovered, would be susceptible to unauthorized access and manipulation without proper authorization checks. The absence of taint analysis results also means that potential vulnerabilities within data processing flows might not have been detected.
In conclusion, while the plugin avoids common pitfalls like SQL injection and unpatched vulnerabilities, the critical weakness in output escaping and the lack of any authorization checks on potential entry points represent significant security risks that need immediate attention. The plugin's strengths lie in its avoidance of known dangerous code patterns and its clean vulnerability history, but its weaknesses in output sanitization and access control are substantial.
Key Concerns
- Low output escaping (8%)
- No nonce checks
- No capability checks
Author List Security Vulnerabilities
Author List Release Timeline
Author List Code Analysis
Output Escaping
Author List Attack Surface
WordPress Hooks 2
Maintenance & Trust
Author List Maintenance & Trust
Maintenance Signals
Community Trust
Author List Alternatives
WP Default Author
wp-default-author
Changes the default author either gobally or for individual users.
Author List
author-role-list
Create a Page for users with their roles. With this plugin, you can create different pages as per its user role. This plugin is applicable to any of t …
Display Current Author on Menu
display-current-author-on-menu
Tiny plugin that allows you to display current author's name(Display Name) on menu.
Kento Top Author
kento-top-authors
Top Author list By Count Post
List-all-authors
list-all-authors
Das Plugin ermoeglicht die Auflistung aller Authoren, auch solcher, die noch keine Artikel geschrieben haben. The plugin lets you lists all authors, even those without posts.
Author List Developer Profile
21 plugins · 4K total installs
How We Detect Author List
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/author-list/css/bc-author-list.css/wp-content/plugins/author-list/css/tooltip.cssHTML / DOM Fingerprints
buffercode_author_list_infoid="buffercode_author_list_img_size"<li class="author-list-<a href="class="tooltip"><h4>