
Change Author Security & Risk Analysis
wordpress.org/plugins/change-authorThis plugin lets you assign non-authors as post author.
Is Change Author Safe to Use in 2026?
Generally Safe
Score 85/100Change Author has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "change-author" plugin v1.3 exhibits a strong security posture based on the provided static analysis. There are no identified attack surface points such as AJAX handlers, REST API routes, shortcodes, or cron events that could be exploited without proper authentication. The code also demonstrates excellent security practices by not utilizing dangerous functions, all SQL queries are prepared, and all outputs are properly escaped. Furthermore, the plugin avoids file operations, external HTTP requests, and incorporates no bundled libraries, all of which reduce potential vulnerabilities. The complete absence of any recorded CVEs, including critical or high severity ones, and the lack of recorded vulnerability history further bolster its security profile. However, the analysis also notes a complete absence of nonce checks and capability checks. While the current lack of an exposed attack surface might mitigate immediate risks, this absence represents a significant potential weakness if new entry points are introduced in future updates or if the plugin's functionality implicitly relies on these checks in ways not apparent from this static analysis alone. The zero taint analysis flows, while positive, could also be attributed to a lack of complex data processing or user interaction within the plugin, which might not reveal underlying issues if they existed.
Key Concerns
- Missing nonce checks
- Missing capability checks
Change Author Security Vulnerabilities
Change Author Code Analysis
Change Author Attack Surface
WordPress Hooks 1
Maintenance & Trust
Change Author Maintenance & Trust
Maintenance Signals
Community Trust
Change Author Alternatives
WP Custom Author Image
author-image
Lets you easily add WP Custom Author Images on your site.
Edit Author Slug
edit-author-slug
Allows an admin (or capable user) to edit the author slug of a user, and change the author base.
Co-Authors Plus
co-authors-plus
Assign multiple bylines to posts, pages, and custom post types with a search-as-you-type input box.
Meks Smart Author Widget
meks-smart-author-widget
Easily display your author/user profile info inside WordPress widget.
Starbox – the Author Box for Humans
starbox
Starbox is the Author Box for Humans. Professional Themes to choose from, HTML5, Social Media Profiles, Google Authorship
Change Author Developer Profile
2 plugins · 1K total installs
How We Detect Change Author
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/change-author/css/style.csschange-author/css/style.css?ver=HTML / DOM Fingerprints
screen-reader-text