
Author Grid Security & Risk Analysis
wordpress.org/plugins/authorgridSidebar widget that displays the avatar of all of the authors on your blog in grid form.
Is Author Grid Safe to Use in 2026?
Generally Safe
Score 85/100Author Grid has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "authorgrid" v1 plugin exhibits a strong security posture based on the provided static analysis. The absence of any identified attack surface points, dangerous functions, file operations, external HTTP requests, or nonce/capability checks is highly commendable. This indicates that the plugin has been developed with security best practices in mind, minimizing potential entry points for attackers. The taint analysis also shows no critical or high severity vulnerabilities, further reinforcing its secure design.
However, there are areas that warrant attention. A significant concern is the low percentage of properly escaped output (11%), with 18 total outputs. This suggests that a substantial number of data outputs are not being sanitized, potentially leading to cross-site scripting (XSS) vulnerabilities if user-supplied data is displayed without proper escaping. While the SQL queries are partially using prepared statements, the fact that 50% are not prepared introduces a risk of SQL injection. The lack of any recorded CVEs is a positive sign, but it's crucial to remember that a clean history does not guarantee future security, especially when combined with the identified output escaping and SQL preparation weaknesses.
In conclusion, "authorgrid" v1 has a fundamentally secure architecture by limiting its attack surface. The primary risks lie in the potential for XSS and SQL injection due to insufficient output escaping and raw SQL queries, respectively. Continuous monitoring and updates are essential, particularly addressing the output escaping and SQL preparation issues to maintain its strong security standing.
Key Concerns
- Low output escaping percentage (11%)
- 50% of SQL queries not using prepared statements
Author Grid Security Vulnerabilities
Author Grid Release Timeline
Author Grid Code Analysis
SQL Query Safety
Output Escaping
Author Grid Attack Surface
WordPress Hooks 1
Maintenance & Trust
Author Grid Maintenance & Trust
Maintenance Signals
Community Trust
Author Grid Alternatives
Authors List
authors-list
Use a shortcode to display a list or grid of post authors (or any other user role) and links to their post archives page.
GoSMTP – SMTP for WordPress
gosmtp
Send emails from your WordPress site using your preferred SMTP provider like Gmail, Outlook, AWS, Zoho, SMTP.com, Brevo (formerly Sendinblue), Mailgun …
Layout Grid Block
layout-grid
A Gutenberg container block to let you align items consistently across a global grid.
Content Views – Post Grid & Filter, Recent Posts, Category Posts … (Shortcode, Gutenberg Blocks, and Widgets for Elementor)
content-views-query-and-display-post-page
Easy to show posts, pages, custom posts in customizable grid, list, slider, accordion... Available as Widgets (for Elementor), Shortcode, and Blocks.
The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid
the-post-grid
Display WordPress posts in beautiful grid, list, slider, and filter layouts. Works with Gutenberg, Elementor, Divi, and Shortcodes.
Author Grid Developer Profile
1 plugin · 10 total installs
How We Detect Author Grid
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/authorgrid/authorGrid.phpHTML / DOM Fingerprints
<div style="padding: 0px; width: px; margin-left: 5px; margin-top: 3px;"><a href="" style="margin-right: 1px;">