
Contributor Security & Risk Analysis
wordpress.org/plugins/contributorContributor Plugin display just more than one author-name on a post.
Is Contributor Safe to Use in 2026?
Generally Safe
Score 85/100Contributor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "contributor" plugin v1.0.0 exhibits a strong security posture based on the provided static analysis. There are no identified entry points like AJAX handlers, REST API routes, shortcodes, or cron events that are exposed to users. Furthermore, the code demonstrates excellent security practices with no dangerous functions, all SQL queries using prepared statements, and all output properly escaped. The absence of file operations and external HTTP requests further reduces the potential attack surface. The taint analysis also shows no concerning flows, indicating that data is handled safely within the plugin.
The vulnerability history is equally positive, with no recorded CVEs of any severity. This lack of past vulnerabilities, combined with the current clean static analysis, suggests that the developers have a good understanding of WordPress security best practices and have likely maintained a high standard throughout the plugin's development. However, the complete absence of any capability checks or nonce checks on the identified (albeit zero) entry points is a slight concern, as these are fundamental WordPress security mechanisms. While there are no entry points to check currently, this could indicate a potential oversight if future versions introduce such points without implementing these checks.
In conclusion, "contributor" v1.0.0 appears to be a very secure plugin with no immediate exploitable vulnerabilities. The developers have clearly prioritized secure coding practices. The only minor weakness is the complete lack of capability and nonce checks, which, while not an issue for the current version, could become a risk if the plugin evolves and adds exposed functionalities without incorporating these essential security measures.
Key Concerns
- Missing capability checks
- Missing nonce checks
Contributor Security Vulnerabilities
Contributor Code Analysis
Output Escaping
Contributor Attack Surface
WordPress Hooks 8
Maintenance & Trust
Contributor Maintenance & Trust
Maintenance Signals
Community Trust
Contributor Alternatives
Coopso Contributors
coopso-contributors
WordPress contributors plugin. The user(admin, author, and editor) can select the multiple users who contribute to the post and at the front end after …
Posts Contributors
posts-contributors
This is a simple posts contributors for WordPress posts plugin.
WP Post Contributor
wp-post-contributor
WP Post Contributors plugin allows you to add more than one author to the post who have contributed.
WP SimplePost Contributors
wp-simplepost-contributors
Add more than one author to the post.
WP Multi Author
wp-multi-author
One post, multiple contributors!
Contributor Developer Profile
2 plugins · 0 total installs
How We Detect Contributor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/contributor/admin/css/contributor-admin.css/wp-content/plugins/contributor/admin/js/contributor-admin.js/wp-content/plugins/contributor/admin/js/contributor-admin.jscontributor-admin.css?ver=contributor-admin.js?ver=HTML / DOM Fingerprints
id="contributor-meta-box"id="contributorForm"