Genesis Co-Authors Plus Security & Risk Analysis

wordpress.org/plugins/genesis-co-authors-plus

Enables full support for the Co-Authors Plus plugin in Genesis.

100 active installs v1.3 PHP + WP 3.0+ Updated Feb 23, 2014
co-authorsco-authors-plusgenesismultiple-authors
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Genesis Co-Authors Plus Safe to Use in 2026?

Generally Safe

Score 85/100

Genesis Co-Authors Plus has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The Genesis Co-Authors Plus plugin version 1.3 presents a generally good security posture, with no known historical vulnerabilities (CVEs) and a code analysis that indicates no critical or high severity issues. The absence of dangerous functions, file operations, external HTTP requests, and the use of prepared statements for SQL queries are all positive signs. Taint analysis showing zero unsanitized paths further reinforces this. However, there are notable areas for improvement. The plugin lacks nonce checks and capability checks, which are crucial for preventing unauthorized actions, especially on its single shortcode entry point. Furthermore, 100% of its output is not properly escaped, posing a significant risk for Cross-Site Scripting (XSS) vulnerabilities, particularly if the shortcode processes user-supplied data. While the plugin has a clean history, the identified weaknesses in input validation and output escaping mean that it could be susceptible to attacks if not addressed.

Key Concerns

  • Output not properly escaped
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Genesis Co-Authors Plus Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Genesis Co-Authors Plus Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

Genesis Co-Authors Plus Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[post_authors_post_link] genesis-coauthors.php:55
WordPress Hooks 3
filtergenesis_post_infogenesis-coauthors.php:68
actiongenesis_after_entrygenesis-coauthors.php:78
actioninitgenesis-coauthors.php:80
Maintenance & Trust

Genesis Co-Authors Plus Maintenance & Trust

Maintenance Signals

WordPress version tested3.7.41
Last updatedFeb 23, 2014
PHP min version
Downloads6K

Community Trust

Rating100/100
Number of ratings2
Active installs100
Developer Profile

Genesis Co-Authors Plus Developer Profile

Jean

6 plugins · 340 total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Genesis Co-Authors Plus

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/genesis-co-authors-plus/genesis-co-authors-plus.php
Version Parameters
genesis-co-authors-plus.php?ver=/wp-content/plugins/genesis-co-authors-plus/genesis-co-authors-plus.php?ver=

HTML / DOM Fingerprints

CSS Classes
author-box-titleauthor-box-content
Data Attributes
genesis-attr("author-box")
Shortcode Output
[post_authors_post_link]
FAQ

Frequently Asked Questions about Genesis Co-Authors Plus