DT Author Box Security & Risk Analysis

wordpress.org/plugins/dt-author-box

Easily add an author box bio signature with custom profile image and social profile buttons to the end of each author's posts

50 active installs v1.2.2 PHP + WP 3.1.2+ Updated Jun 13, 2019
authorauthor-boxavatarprofilesignature
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is DT Author Box Safe to Use in 2026?

Generally Safe

Score 85/100

DT Author Box has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The dt-author-box v1.2.2 plugin exhibits a strong security posture based on the provided static analysis. The absence of any identified attack surface entry points (AJAX handlers, REST API routes, shortcodes, cron events) is a significant strength, indicating that the plugin likely doesn't expose direct user-manipulable interfaces. The code signals further reinforce this, with no dangerous functions, no raw SQL queries, and excellent output escaping (94% properly escaped). The presence of a capability check is also a positive sign for authorization. Taint analysis revealing no unsanitized flows further supports a low-risk profile.

Despite the excellent static analysis results and a clean vulnerability history, the lack of explicit nonce checks (0 reported) across all potential (though currently nonexistent) entry points is a minor concern. While there's no current attack surface to exploit this, it's a best practice to include nonces for any future additions or if the analysis missed subtle integration points. Overall, the plugin appears to be well-developed from a security perspective, with a minimal attack surface and robust code hygiene. The lack of any historical vulnerabilities further strengthens this positive assessment.

Key Concerns

  • Missing nonce checks detected
Vulnerabilities
None known

DT Author Box Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

DT Author Box Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
17 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

94% escaped18 total outputs
Attack Surface

DT Author Box Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionshow_user_profiledt_authorbox.php:37
actionedit_user_profiledt_authorbox.php:38
actionpersonal_options_updatedt_authorbox.php:128
actionedit_user_profile_updatedt_authorbox.php:129
actionwp_enqueue_scriptsdt_authorbox.php:148
filterthe_contentdt_authorbox.php:223
actionadmin_headdt_authorbox.php:251
Maintenance & Trust

DT Author Box Maintenance & Trust

Maintenance Signals

WordPress version tested3.6.1
Last updatedJun 13, 2019
PHP min version
Downloads16K

Community Trust

Rating100/100
Number of ratings1
Active installs50
Developer Profile

DT Author Box Developer Profile

DigitalTweaker

1 plugin · 50 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect DT Author Box

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/dt-author-box/css/style.php
Version Parameters
dt-author-box/css/style.php?ver=custom-style?ver=

HTML / DOM Fingerprints

CSS Classes
dt-author-boxdt-author-box-socialdt-author-box-content
Data Attributes
data-dt-twitterdata-dt-facebookdata-dt-linkedindata-dt-googleplusdata-dt-youtubedata-dt-pinterest+2 more
FAQ

Frequently Asked Questions about DT Author Box