
Authorsy – Author Box, Multiple Authors, Guest Authors & Post Rating Security & Risk Analysis
wordpress.org/plugins/authorsyAuthorsy is a powerful WordPress author box plugin. Add customizable author profiles, multiple authors, guest authors, bios, social links, and post ra …
Is Authorsy – Author Box, Multiple Authors, Guest Authors & Post Rating Safe to Use in 2026?
Generally Safe
Score 98/100Authorsy – Author Box, Multiple Authors, Guest Authors & Post Rating has a strong security track record. Known vulnerabilities have been patched promptly.
The "authorsy" plugin v1.0.7 exhibits a generally good security posture, particularly in its handling of SQL queries and output escaping, with a very high percentage of outputs properly escaped and all SQL queries utilizing prepared statements. The presence of nonce and capability checks further bolsters its defense against common web vulnerabilities. The static analysis reveals a small attack surface with no directly unprotected entry points.
However, the use of the "preg_replace(/e)" dangerous function is a notable concern. While taint analysis did not reveal any immediate unsanitized paths, this function, if misused, can be a vector for code injection or unintended regular expression evaluation, potentially leading to security issues. The plugin's vulnerability history, with two known medium-severity CVEs related to Authorization Bypass and Cross-site Scripting, even though currently unpatched, indicates a past susceptibility to critical vulnerability types.
The plugin's strengths lie in its robust input sanitization and authorization mechanisms. Nevertheless, the historical presence of vulnerabilities and the identified dangerous function warrant caution. While the current version appears to have addressed past issues and has a small attack surface, vigilance regarding the "preg_replace(/e)" usage and awareness of past vulnerability types is recommended.
Key Concerns
- Use of dangerous function preg_replace(/e)
- History of medium severity CVEs (2 total)
Authorsy – Author Box, Multiple Authors, Guest Authors & Post Rating Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Authorsy <= 1.0.6 - Unauthenticated Insecure Direct Object Reference
Authorsy – Author Box, Multiple Authors, Guest Authors & Post Rating <= 1.0.5 - Authenticated (Subscriber+) Stored Cross-Site Scripting
Authorsy – Author Box, Multiple Authors, Guest Authors & Post Rating Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Authorsy – Author Box, Multiple Authors, Guest Authors & Post Rating Attack Surface
Shortcodes 2
WordPress Hooks 22
Maintenance & Trust
Authorsy – Author Box, Multiple Authors, Guest Authors & Post Rating Maintenance & Trust
Maintenance Signals
Community Trust
Authorsy – Author Box, Multiple Authors, Guest Authors & Post Rating Alternatives
Simple Author Box
simple-author-box
Add a responsive author box or guest author box with social icons to any post. Great author box for any site!
Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors
publishpress-authors
PublishPress Authors is the best plugin for adding authors, co-authors, multiple authors and guest authors to WordPress posts.
Molongui Authorship – Author Boxes, Guest Authors & Co-Authors for WordPress
molongui-authorship
All-in-One Authorship Solution: Seamless Author Box, Guest Authors, and Co-Authors to enhance your site's authority, credibility, engagement, and SEO.
Starbox – the Author Box for Humans
starbox
Starbox is the Author Box for Humans. Professional Themes to choose from, HTML5, Social Media Profiles, Google Authorship
WP Post Author – Author Box, Co-Authors & Guest Authors
wp-post-author
WP Post Author provides a complete solution for displaying author information, managing multiple authors, collecting post ratings, and creating user r …
Authorsy – Author Box, Multiple Authors, Guest Authors & Post Rating Developer Profile
1 plugin · 1K total installs
How We Detect Authorsy – Author Box, Multiple Authors, Guest Authors & Post Rating
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/authorsy/assets/css/authorsy-public.css/wp-content/plugins/authorsy/assets/js/authorsy-public.js/wp-content/plugins/authorsy/assets/css/authorsy-admin.css/wp-content/plugins/authorsy/assets/js/authorsy-admin.js/wp-content/plugins/authorsy/assets/js/authorsy-public.js/wp-content/plugins/authorsy/assets/js/authorsy-admin.jsauthorsy/assets/css/authorsy-public.css?ver=authorsy/assets/js/authorsy-public.js?ver=authorsy/assets/css/authorsy-admin.css?ver=authorsy/assets/js/authorsy-admin.js?ver=HTML / DOM Fingerprints
authorsy-author-boxauthorsy-avatarauthorsy-author-nameauthorsy-author-bioauthorsy-social-linksauthorsy-admin-noticedata-authorsy-idauthorsy_public_params