
Global Food Book's Author Biography Widget Security & Risk Analysis
wordpress.org/plugins/gfb-author-bio-widgetThis makes it easy to setup a brief synopsis of the author's biography on the sidebar. Best used in food & cook theme or woo-themes.
Is Global Food Book's Author Biography Widget Safe to Use in 2026?
Generally Safe
Score 85/100Global Food Book's Author Biography Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The gfb-author-bio-widget plugin, version 1.1, exhibits a mixed security posture. On the positive side, it has no known vulnerabilities in its history, and its static analysis shows no SQL injection risks due to the use of prepared statements, no file operations, and no external HTTP requests. Furthermore, the attack surface appears to be entirely protected by authentication checks, with zero unprotected entry points like AJAX handlers, REST API routes, shortcodes, or cron events. This indicates a generally cautious approach to common web attack vectors.
However, there are notable concerns. The presence of the `create_function` PHP function is a significant red flag, as it is deprecated and can lead to code execution vulnerabilities if not handled with extreme care, especially in older PHP versions. Additionally, a substantial portion of the plugin's output (66%) is not properly escaped. This leaves it vulnerable to Cross-Site Scripting (XSS) attacks, where malicious scripts could be injected into the plugin's output and executed in the user's browser. The lack of any identified taint flows in the static analysis might be due to the limited scope of the analysis or the nature of the detected `create_function` usage, which might not have been flagged as a taint source in this specific analysis.
In conclusion, while the plugin benefits from a small attack surface, robust authentication on entry points, and a clean vulnerability history, the use of `create_function` and significant unescaped output present serious security risks. These weaknesses, if exploited, could lead to code execution and XSS vulnerabilities, respectively. The plugin's strengths lie in its protected entry points and lack of historical CVEs, but the identified code-level issues require immediate attention.
Key Concerns
- Presence of dangerous function: create_function
- High percentage of unescaped output
- No nonce checks
- No capability checks
Global Food Book's Author Biography Widget Security Vulnerabilities
Global Food Book's Author Biography Widget Code Analysis
Dangerous Functions Found
Output Escaping
Global Food Book's Author Biography Widget Attack Surface
WordPress Hooks 1
Maintenance & Trust
Global Food Book's Author Biography Widget Maintenance & Trust
Maintenance Signals
Community Trust
Global Food Book's Author Biography Widget Alternatives
RS Author Info Box
rs-author-info-box
A simple and lightweight widget to display an author's name, profile image, short description, and social media links in any sidebar or widget area.
Kantbtrue about me
kantbtrue-about-me
An elegant about me widget and profile widget for blogs. With this plugin you can add title, description with links, profile image and social links.
Simple Author Bio
simple-author-bio
Plugin that shows the author's biography in the foot of the posts.
Author Bio Shortcode
author-bio-shortcode
Provides the [author_bio] shortcode for embedding the bio of an author anywhere in the post/page content.
Author Box by Nocksoft
author-box-by-nocksoft
Adds a modern author info box at the end of your posts and implements local avatars as an alternative to Gravatar.
Global Food Book's Author Biography Widget Developer Profile
3 plugins · 30 total installs
How We Detect Global Food Book's Author Biography Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
widget-gfb-author-biodata-widget-id