
Author Profile Plus Security & Risk Analysis
wordpress.org/plugins/author-profile-plusSupercharge your WordPress user profiles with Author Profile Plus
Is Author Profile Plus Safe to Use in 2026?
Generally Safe
Score 85/100Author Profile Plus has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The author-profile-plus plugin v0.8.2 presents a mixed security posture. While it demonstrates strengths in avoiding dangerous functions, file operations, external HTTP requests, and utilizes prepared statements for its SQL queries, significant concerns arise from its attack surface and output handling. The presence of an unprotected AJAX handler is a critical vulnerability, providing a direct entry point for attackers. Furthermore, the extremely low percentage of properly escaped output signals a high risk of cross-site scripting (XSS) vulnerabilities, as user-supplied data is likely being rendered directly into the page without sanitization.
The absence of any recorded CVEs is positive, suggesting a lack of publicly known exploits. However, this should not be interpreted as a guarantee of security, especially given the identified code weaknesses. The taint analysis, while showing no critical or high severity flows, did reveal flows with unsanitized paths, which, when combined with the unprotected entry point, warrants further investigation for potential exploitation.
In conclusion, the plugin's most pressing issues are the unprotected AJAX endpoint and the widespread lack of output escaping. These weaknesses significantly outweigh the strengths in other areas, creating a notable risk profile. Users should be cautious until these issues are addressed. The lack of vulnerability history, coupled with the observed code issues, suggests that the plugin may have been overlooked by security researchers or that potential vulnerabilities have not yet been discovered or disclosed.
Key Concerns
- Unprotected AJAX handler
- Low percentage of properly escaped output
- Flows with unsanitized paths
- No nonce checks on AJAX
- No capability checks
Author Profile Plus Security Vulnerabilities
Author Profile Plus Code Analysis
Output Escaping
Data Flow Analysis
Author Profile Plus Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
Author Profile Plus Maintenance & Trust
Maintenance Signals
Community Trust
Author Profile Plus Alternatives
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
ultimate-member
Membership & community plugin with user profiles, registration & login, member directories, content restriction, user roles and much more.
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
wp-user-avatar
Setup paid membership, accept payment, sell subscription & digital product, paywall, create login & registration form, user profile & member directory
User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder
user-registration
Build membership sites with tiered plans, content restriction, drag-&-drop custom registration & login form builder, and built-in payment system.
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor
profile-builder
Powerful user profile plugin to create front-end user registration forms, login & user profile forms. Includes user role editor & content restriction.
User Profile Picture
metronet-profile-picture
Set a custom profile image (avatar) for a user using the standard WordPress media upload tool.
Author Profile Plus Developer Profile
4 plugins · 710 total installs
How We Detect Author Profile Plus
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/author-profile-plus/assets/css/font-awesome.min.css/wp-content/plugins/author-profile-plus/assets/css/theme.css/wp-content/plugins/author-profile-plus/assets/css/style.css/wp-content/plugins/author-profile-plus/assets/js/scripts.js/wp-content/plugins/author-profile-plus/assets/js/scripts.jsauthor-profile-plus/assets/css/font-awesome.min.css?ver=author-profile-plus/assets/css/theme.css?ver=author-profile-plus/assets/css/style.css?ver=author-profile-plus/assets/js/scripts.js?ver=HTML / DOM Fingerprints
author-profileauthor-profile-aboutbioavatargravatar-wrappersocialfa-facebook-square+13 moredata-app_author_namedata-app_author_biodata-app_author_avatardata-app_author_facebookdata-app_author_twitterdata-app_author_gplus+1 moreAJAX<div class="author-profile author-profile-<p class="about">About <blockquote class="bio"><ul class="social">