
Author Spotlight (Widget) Security & Risk Analysis
wordpress.org/plugins/author-profileA Sidebar widget to display the Author(s) profile on any Page or Post along with Social web links.
Is Author Spotlight (Widget) Safe to Use in 2026?
Generally Safe
Score 85/100Author Spotlight (Widget) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The author-profile plugin v3.4 presents a mixed security posture. On the positive side, there are no known vulnerabilities (CVEs) recorded for this plugin, and the static analysis shows a complete absence of dangerous file operations and external HTTP requests. Furthermore, all SQL queries are properly prepared, and there are no observed taint flows indicating a lack of critical sanitation issues. This suggests that the developers have a foundational understanding of some secure coding practices, particularly concerning database interactions and avoiding common web attack vectors.
However, significant security concerns are raised by the lack of any authentication or capability checks across all identified entry points. The use of the `create_function` function is a critical security risk, as it is highly susceptible to code injection vulnerabilities if its input is not strictly sanitized. Additionally, a substantial portion of the output (71%) is not properly escaped, presenting a high risk of Cross-Site Scripting (XSS) vulnerabilities. The absence of nonce checks on AJAX handlers, if any were present (though the analysis shows 0), would also be a significant concern.
Given the absence of known CVEs and the clean taint analysis, the plugin might appear secure at first glance. However, the identified code signals, specifically the use of `create_function` and the widespread lack of output escaping, represent substantial and exploitable vulnerabilities that are likely to be present. These issues, combined with the complete lack of authorization checks on any entry points, paint a picture of a plugin that, while not having a public vulnerability history, is insecure by design and highly susceptible to attacks.
Key Concerns
- Use of dangerous function 'create_function'
- Low percentage of properly escaped output (29%)
- No capability checks on entry points
- No nonce checks on entry points
Author Spotlight (Widget) Security Vulnerabilities
Author Spotlight (Widget) Code Analysis
Dangerous Functions Found
Output Escaping
Author Spotlight (Widget) Attack Surface
WordPress Hooks 1
Maintenance & Trust
Author Spotlight (Widget) Maintenance & Trust
Maintenance Signals
Community Trust
Author Spotlight (Widget) Alternatives
Authorsy – Author Box, Multiple Authors, Guest Authors & Post Rating
authorsy
Authorsy is a powerful WordPress author box plugin. Add customizable author profiles, multiple authors, guest authors, bios, social links, and post ra …
Simple Author Box
simple-author-box
Add a responsive author box or guest author box with social icons to any post. Great author box for any site!
WP Post Author – Author Box, Co-Authors & Guest Authors
wp-post-author
WP Post Author provides a complete solution for displaying author information, managing multiple authors, collecting post ratings, and creating user r …
Cool Author Box – For Widget and Post Content
hm-cool-author-box-widget
Cool Author Box displays an responsive author box with social media links to your widget and post content area.
Smart Author Box Widget
smart-author-box-widget
Smart Author Box Widget displays author bio box with an image, description, and social links—perfect for multi-author blogs and personal sites.
Author Spotlight (Widget) Developer Profile
3 plugins · 710 total installs
How We Detect Author Spotlight (Widget)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/author-profile/images/twitter.png/wp-content/plugins/author-profile/images/facebook.png/wp-content/plugins/author-profile/images/linkedin.png/wp-content/plugins/author-profile/images/googleplus.png/wp-content/plugins/author-profile/images/youtube.png/wp-content/plugins/author-profile/images/myspace.png/wp-content/plugins/author-profile/images/flickr.png/wp-content/plugins/author-profile/images/skype.png+3 moreauthor-profile/css/author-profile-style.css?ver=HTML / DOM Fingerprints
AuthorSpotlight_Widgetauthor-spotlightauthor-profilesocial-iconsauthor-descriptiondata-username