
CW Author Info Security & Risk Analysis
wordpress.org/plugins/cw-author-infoAdd a box with information about the author of each post after post, include a widget in which appear a list of all components of the blog
Is CW Author Info Safe to Use in 2026?
Generally Safe
Score 100/100CW Author Info has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The cw-author-info plugin v1.1.1 exhibits a generally good security posture with no known CVEs and a complete absence of SQL injection vulnerabilities due to the consistent use of prepared statements. The plugin also avoids risky operations like file manipulation and external HTTP requests. However, the static analysis reveals significant concerns regarding output escaping, with only 32% of outputs being properly sanitized. This presents a considerable risk of Cross-Site Scripting (XSS) vulnerabilities, especially given the two identified taint flows with unsanitized paths. While the taint analysis did not flag critical or high severity issues, the presence of unsanitized paths indicates potential vulnerabilities that could be exploited if user-supplied data is not handled correctly before being rendered. The lack of explicit capability checks and nonce checks on entry points (even though the attack surface is reported as zero) is a minor concern, as it doesn't follow best practices for all WordPress plugins, though it doesn't currently pose a direct risk given the limited entry points. The bundled jQuery v1.4.4 is significantly outdated and could be a vector for known vulnerabilities if the plugin were to utilize its features in an insecure manner. Overall, the plugin is strong in avoiding direct database or file system risks, but the high rate of unescaped output and unsanitized paths are critical weaknesses that require immediate attention.
Key Concerns
- Low percentage of properly escaped output
- Taint flows with unsanitized paths
- Bundled outdated jQuery library
CW Author Info Security Vulnerabilities
CW Author Info Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
CW Author Info Attack Surface
WordPress Hooks 10
Maintenance & Trust
CW Author Info Maintenance & Trust
Maintenance Signals
Community Trust
CW Author Info Alternatives
Simple Author Box
simple-author-box
Add a responsive author box or guest author box with social icons to any post. Great author box for any site!
WP Post Author – Author Box, Co-Authors & Guest Authors
wp-post-author
WP Post Author provides a complete solution for displaying author information, managing multiple authors, collecting post ratings, and creating user r …
Authorsy – Author Box, Multiple Authors, Guest Authors & Post Rating
authorsy
Authorsy is a powerful WordPress author box plugin. Add customizable author profiles, multiple authors, guest authors, bios, social links, and post ra …
Cool Author Box – For Widget and Post Content
hm-cool-author-box-widget
Cool Author Box displays an responsive author box with social media links to your widget and post content area.
Smart Author Box Widget
smart-author-box-widget
Smart Author Box Widget displays author bio box with an image, description, and social links—perfect for multi-author blogs and personal sites.
CW Author Info Developer Profile
2 plugins · 20 total installs
How We Detect CW Author Info
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cw-author-info/css/author_box.csshttp://meta100.github.com/mColorPicker/javascripts/mColorPicker_min.jsHTML / DOM Fingerprints
author_post_biocw_author_nameavatarsocial_authorname="cw_facebook"name="cw_twitter"name="cw_google_plus"name="color_picker_color1"name="color_picker_color2"name="color_picker_color3"+2 more