
Display Authors Widget Security & Risk Analysis
wordpress.org/plugins/display-authors-widgetDisplay authors by role.
Is Display Authors Widget Safe to Use in 2026?
Generally Safe
Score 85/100Display Authors Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "display-authors-widget" plugin version 1.1.1 exhibits a generally good security posture, primarily due to its minimal attack surface and lack of known vulnerabilities. The analysis reveals no external entry points like AJAX handlers, REST API routes, shortcodes, or cron events that are exposed without authentication or permission checks, which is a significant strength. Furthermore, all SQL queries utilize prepared statements, and there are no file operations or external HTTP requests, reducing the potential for common attack vectors.
However, there are areas of concern. The use of the deprecated `create_function` is a red flag, as it can be a source of security vulnerabilities if not handled with extreme care, although in this specific case, no taint flows were detected. More critically, only 5% of output is properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. With 43 total outputs, this means a substantial number are likely vulnerable to attackers injecting malicious scripts.
Given the absence of known CVEs and a clean vulnerability history, the plugin appears to have been developed with some security awareness. However, the significant number of unescaped outputs presents a clear and present danger that could be easily exploited. The plugin's strengths lie in its limited attack surface and safe database interactions, but the output escaping deficiency represents a major weakness that needs immediate attention.
Key Concerns
- Insufficient output escaping
- Use of deprecated create_function
Display Authors Widget Security Vulnerabilities
Display Authors Widget Code Analysis
Dangerous Functions Found
Output Escaping
Display Authors Widget Attack Surface
WordPress Hooks 3
Maintenance & Trust
Display Authors Widget Maintenance & Trust
Maintenance Signals
Community Trust
Display Authors Widget Alternatives
Co-Authors Widget
widget-for-co-authors
The plugin add a widget and a shortcode in order to show authors of an article. It is compatible with Co-Authors Plus.
Recent Posts With Authors Widget
recent-posts-with-authors-widget
Shows a list of recent posts with the author of each post - for multi-author blogs.
Co-Authors Plus
co-authors-plus
Assign multiple bylines to posts, pages, and custom post types with a search-as-you-type input box.
Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors
publishpress-authors
PublishPress Authors is the best plugin for adding authors, co-authors, multiple authors and guest authors to WordPress posts.
Molongui Authorship – Author Boxes, Guest Authors & Co-Authors for WordPress
molongui-authorship
All-in-One Authorship Solution: Seamless Author Box, Guest Authors, and Co-Authors to enhance your site's authority, credibility, engagement, and SEO.
Display Authors Widget Developer Profile
5 plugins · 230 total installs
How We Detect Display Authors Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/display-authors-widget/display-authors-widget.phpHTML / DOM Fingerprints
display-authors-widgetauthor-profiledisplay-authors-widget-alignleftdisplay-authors-widget-alignrightid="hcard-class="author-profile vcard clear"class="display-authors-widget-id="display-authors-widgetname="display-authors-widget