
Author Post Ratings Security & Risk Analysis
wordpress.org/plugins/author-post-ratingsAllows a post author to assign a simple 1-5 star rating to a post, page, or custom post type, which will then be displayed on the post.
Is Author Post Ratings Safe to Use in 2026?
Generally Safe
Score 85/100Author Post Ratings has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The author-post-ratings plugin version 1.1.1 exhibits a generally good security posture, with no known vulnerabilities in its history and strong adherence to common WordPress security practices in its static analysis. The plugin demonstrates a low attack surface, with a single shortcode as its only entry point, and importantly, all identified code signals indicate proper security measures are in place. Specifically, there are no dangerous functions, SQL queries are exclusively handled via prepared statements, and file operations and external HTTP requests are absent. Furthermore, the presence of nonce and capability checks suggests that access controls are being considered. However, a notable concern arises from the output escaping analysis, where only 40% of the total 10 outputs are properly escaped. This indicates a potential for cross-site scripting (XSS) vulnerabilities if user-supplied data or dynamic content is not sufficiently sanitized before being rendered on the frontend.
While the plugin's vulnerability history is clean, which is a positive sign of diligent development, the static analysis finding regarding output escaping warrants attention. The lack of taint analysis results also doesn't confirm the absence of complex vulnerabilities, but the absence of concerning code signals like raw SQL or dangerous functions is reassuring. The overall conclusion is that while the plugin appears robust and well-maintained, the unescaped output presents a specific, actionable security risk that should be addressed to achieve a truly secure implementation.
Key Concerns
- Only 40% of output properly escaped
Author Post Ratings Security Vulnerabilities
Author Post Ratings Code Analysis
Output Escaping
Author Post Ratings Attack Surface
Shortcodes 1
WordPress Hooks 8
Maintenance & Trust
Author Post Ratings Maintenance & Trust
Maintenance Signals
Community Trust
Author Post Ratings Alternatives
Author Filters
author-filters
Author filters plugin integrates an author filter drop down to sort listing on post, page, custom post type in admin.
EC Stars Rating
ec-stars-rating
A lightweigt, blazing fast star rating plugin for WordPress
Custom Ratings
custom-ratings
A fun and creative way to let your site visitors rate your posts, pages, and more!
All in one demo Export/Import
all-in-one-demo-importexport
Easily export or import your WordPress customizer settings!
Latest Users Dashboard Widget
latest-users-dashboard-widget
Latest Users Dashboard Widget extension integrates a welcome widget to display new users added to the system in a tabular format.
Author Post Ratings Developer Profile
7 plugins · 4K total installs
How We Detect Author Post Ratings
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/author-post-ratings/author-post-ratings.cssHTML / DOM Fingerprints
author-post-ratingauthor-post-rating-labelauthor-post-rating-starsname="pn_apr_rating"id="pn_apr_rating"[author-post-rating]