
Co-Authors Plus Security & Risk Analysis
wordpress.org/plugins/co-authors-plusAssign multiple bylines to posts, pages, and custom post types with a search-as-you-type input box.
Is Co-Authors Plus Safe to Use in 2026?
Generally Safe
Score 99/100Co-Authors Plus has a strong security track record. Known vulnerabilities have been patched promptly.
The "co-authors-plus" plugin v3.7.0 presents a mixed security posture. While it demonstrates strong adherence to secure coding practices in many areas, particularly with a high percentage of prepared SQL statements and properly escaped output, there are notable areas of concern. The presence of two REST API routes without permission callbacks significantly expands the attack surface to potentially unauthenticated users, creating a critical risk. Furthermore, the history of a high-severity "Exposure of Sensitive Information" vulnerability in 2022 suggests a past weakness that, while patched, warrants continued vigilance. The single unsanitized path flow, though not rated as critical or high, also indicates a potential entry point for malicious data manipulation. Overall, the plugin has implemented several good security measures, but the unprotected REST API endpoints and past vulnerability history necessitate careful monitoring and prompt updates.
Key Concerns
- REST API routes without permission callbacks
- Flow with unsanitized path
- High severity CVE in history
Co-Authors Plus Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Co-Authors Plus 3.5 - 3.5.1 - Sensitive Information Disclosure
Co-Authors Plus Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Co-Authors Plus Attack Surface
AJAX Handlers 2
REST API Routes 2
WordPress Hooks 94
Maintenance & Trust
Co-Authors Plus Maintenance & Trust
Maintenance Signals
Community Trust
Co-Authors Plus Alternatives
Extend Co-Authors Plus for FacetWP
extend-co-authors-plus-for-facetwp
Add an Co-Authors facet to FacetWP
Molongui Authorship – Author Boxes, Guest Authors & Co-Authors for WordPress
molongui-authorship
All-in-One Authorship Solution: Seamless Author Box, Guest Authors, and Co-Authors to enhance your site's authority, credibility, engagement, and SEO.
Starbox – the Author Box for Humans
starbox
Starbox is the Author Box for Humans. Professional Themes to choose from, HTML5, Social Media Profiles, Google Authorship
ThemeRuby Multi Authors – Assign Multiple Writers to Posts
themeruby-multi-authors
A lightweight plugin that allows you to assign multiple writers to posts, fast and easy to use.
Byline
byline
Solves the co/multi-author problem without modifying the theme. Uses a custom taxonomy, "Byline," that replaces the Display Author.
Co-Authors Plus Developer Profile
213 plugins · 19.2M total installs
How We Detect Co-Authors Plus
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/co-authors-plus/js/coauthors-plus.js/wp-content/plugins/co-authors-plus/js/coauthors-plus-admin.js/wp-content/plugins/co-authors-plus/css/coauthors-plus.css/wp-content/plugins/co-authors-plus/css/coauthors-plus-admin.css/wp-content/plugins/co-authors-plus/build/index.js/wp-content/plugins/co-authors-plus/js/coauthors-plus.js/wp-content/plugins/co-authors-plus/js/coauthors-plus-admin.js/wp-content/plugins/co-authors-plus/build/index.jsco-authors-plus/js/coauthors-plus.js?ver=co-authors-plus/js/coauthors-plus-admin.js?ver=co-authors-plus/css/coauthors-plus.css?ver=co-authors-plus/css/coauthors-plus-admin.css?ver=co-authors-plus/build/index.js?ver=HTML / DOM Fingerprints
coauthors-add-newcoauthors-removecoauthors-dropdowncoauthors-searchcoauthors-search-resultsauthor-listcoauthors-avatarsdata-coauthors-post-iddata-coauthors-current-authordata-coauthors-max-authorscoauthors_plus_settingsCoAuthorsPlus/wp-json/coauthors-plus/v1/users/wp-json/coauthors-plus/v1/authors<div class="coauthors-content">