
Category Contributors Security & Risk Analysis
wordpress.org/plugins/category-contributorsDisplays a list of contributors from a category, and on posts will list authors who have contributed to the same category.
Is Category Contributors Safe to Use in 2026?
Generally Safe
Score 85/100Category Contributors has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "category-contributors" plugin version 2017.08.13 exhibits a strong static security posture according to the provided analysis. The absence of entry points such as AJAX handlers, REST API routes, shortcodes, and cron events, coupled with zero dangerous function calls, suggests a minimal attack surface and adherence to secure coding practices in these areas. The plugin also demonstrates good practices by using prepared statements for all its SQL queries and avoiding external HTTP requests and file operations. This indicates a low likelihood of common web vulnerabilities like SQL injection or remote code execution originating from these vectors.
However, a significant concern arises from the very low percentage of properly escaped output (18%). This suggests that data rendered to the user or other contexts may not be adequately sanitized, potentially leading to cross-site scripting (XSS) vulnerabilities. The lack of any recorded vulnerabilities in its history is positive, but it doesn't negate the potential risks posed by the unescaped output. The analysis also notes the absence of nonce and capability checks, which, while less critical in the absence of direct entry points, could become a weakness if new entry points are introduced in future updates without corresponding security measures.
In conclusion, while the plugin is strong in its core development practices by avoiding common dangerous functions and SQL injection vectors, the insufficient output escaping presents a notable risk of XSS. The clean vulnerability history is a good sign, but the identified output escaping issue requires attention. The overall security posture is good, but the XSS risk is a significant weakness.
Key Concerns
- Low output escaping rate
Category Contributors Security Vulnerabilities
Category Contributors Code Analysis
Output Escaping
Category Contributors Attack Surface
WordPress Hooks 1
Maintenance & Trust
Category Contributors Maintenance & Trust
Maintenance Signals
Community Trust
Category Contributors Alternatives
Share on Mastodon
share-on-mastodon
Automatically share WordPress posts on Mastodon.
WP REST Yoast Meta
wp-rest-yoast-meta
Adds meta tags as generated by Yoast SEO to the WP REST API. And adds a custom endpoint to retrieve all redirects as they are set in Yoast SEO Premium …
Divi Title Module
mc-divi-title-module
This plugin adds a new module to the Divi builder, it allows to easily insert titles without going through the text module.
Share on Pixelfed
share-on-pixelfed
Automatically share WordPress (image) posts on Pixelfed.
Add Image to RSS Feed
add-image-to-rss-feed
** this plugin is no longer being update. Please feel free to adopt me! **
Category Contributors Developer Profile
17 plugins · 130 total installs
How We Detect Category Contributors
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/category-contributors/style.css/wp-content/plugins/category-contributors/category-contributors.js/wp-content/plugins/category-contributors/category-contributors.jscategory-contributors/style.css?ver=category-contributors.js?ver=HTML / DOM Fingerprints
CategoryContributorsWidgetcategory-contributorsauthor-photoauthor-nameauthor-user-description