
Author Page Views Security & Risk Analysis
wordpress.org/plugins/author-page-viewsAuthor Pageviews is a plugin designed to help CPM monetized content publishers track their individual authors page vies and compensate them.
Is Author Page Views Safe to Use in 2026?
Generally Safe
Score 85/100Author Page Views has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "author-page-views" plugin v1.0 exhibits a mixed security posture. On the positive side, there are no known vulnerabilities, no dangerous functions, and all SQL queries utilize prepared statements, which are strong indicators of good security practices. The plugin also performs capability checks, which is a vital security control. However, there are significant concerns identified in the static analysis. The taint analysis revealed two flows with unsanitized paths, one of which is rated as high severity, indicating a potential for data to be processed without proper validation. Furthermore, only 55% of output escaping is properly done, leaving a substantial portion of output potentially vulnerable to cross-site scripting (XSS) attacks. The absence of nonce checks on AJAX handlers, while the attack surface for AJAX is currently zero, could become a risk if new handlers are added without proper security considerations.
While the plugin has a clean vulnerability history with no recorded CVEs, this does not negate the risks identified in the static analysis. The taint flow issues and the incomplete output escaping are present risks that need to be addressed regardless of past vulnerability records. The plugin's strengths lie in its disciplined SQL handling and capability checks, but the identified taint flow and output escaping issues represent notable weaknesses that could be exploited in real-world scenarios. A comprehensive review and remediation of these issues are recommended to improve the plugin's overall security.
Key Concerns
- High severity taint flow
- Unsanitized paths in taint flow
- Incomplete output escaping
Author Page Views Security Vulnerabilities
Author Page Views Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Author Page Views Attack Surface
WordPress Hooks 9
Maintenance & Trust
Author Page Views Maintenance & Trust
Maintenance Signals
Community Trust
Author Page Views Alternatives
Epic Tracking
epic-tracking
Easy event tracking for WordPress. Point, click, and track — no code, no tag managers, no third-party scripts.
GA Google Analytics – Connect Google Analytics to WordPress
ga-google-analytics
Adds Google Analytics tracking code to your WordPress site. Supports many tracking features.
SlimStat Analytics
wp-slimstat
The leading web analytics plugin for WordPress
Connect Matomo – Analytics Dashboard for WordPress
wp-piwik
Adds Matomo (former Piwik) statistics to your WordPress dashboard and is also able to add the Matomo Tracking Code to your blog.
NewStatPress
newstatpress
NewStatPress (Statpress plugin fork) is a real-time plugin to manage the visits' statistics about your blog (without external web analytics).
Author Page Views Developer Profile
5 plugins · 30 total installs
How We Detect Author Page Views
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/author-page-views/views/date-dropdown.php/wp-content/plugins/author-page-views/views/admin-report.php