Google Plus Authorship Security & Risk Analysis

wordpress.org/plugins/google-plus-authorship

Add Google Plus Profile Picture to Google Search Results. Very Easy to implement! Google authorship for multiple authors

1K active installs v2.6 PHP + WP 3.0+ Updated Nov 28, 2017
authorshipgooglegoogle-authorshipgoogle-plusgoogle-plus-author
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Google Plus Authorship Safe to Use in 2026?

Generally Safe

Score 85/100

Google Plus Authorship has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The google-plus-authorship v2.6 plugin exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events, particularly without authentication checks, indicates a minimal attack surface. The code also demonstrates good practices by utilizing prepared statements for all SQL queries and avoiding dangerous functions and file operations. The presence of capability checks and proper output escaping for the majority of outputs further reinforces this positive assessment.

The static analysis revealed no critical or high-severity issues in taint flows, and the vulnerability history is completely clean, with no known CVEs. This lack of historical vulnerabilities and the robust code signals suggest a well-maintained and secure plugin. However, the analysis does note a small percentage of outputs that are not properly escaped (18%), which, while not flagged as critical in this instance due to the limited attack surface and lack of taint flows, could potentially become an issue if the plugin's functionality were to expand or if new entry points were introduced without proper sanitization.

Overall, google-plus-authorship v2.6 appears to be a secure plugin with a proactive approach to security, evidenced by its clean history and strong code signals. The primary area for minor concern is the small number of unescaped outputs, which warrants ongoing vigilance as the plugin evolves. The lack of any identified vulnerabilities or concerning taint flows is a significant strength.

Key Concerns

  • Unescaped output detected
Vulnerabilities
None known

Google Plus Authorship Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Google Plus Authorship Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
9 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

82% escaped11 total outputs
Attack Surface

Google Plus Authorship Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
filterthe_author_user_urlgoogle-plus-authorhip.php:36
filterget_the_author_user_urlgoogle-plus-authorhip.php:37
filterget_author_posts_urlgoogle-plus-authorhip.php:39
filterthe_author_linkgoogle-plus-authorhip.php:42
filterthe_author_posts_linkgoogle-plus-authorhip.php:43
filterget_the_author_posts_linkgoogle-plus-authorhip.php:44
actionshow_user_profilegoogle-plus-authorhip.php:46
actionedit_user_profilegoogle-plus-authorhip.php:47
actionprofile_updategoogle-plus-authorhip.php:81
Maintenance & Trust

Google Plus Authorship Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.32
Last updatedNov 28, 2017
PHP min version
Downloads87K

Community Trust

Rating86/100
Number of ratings8
Active installs1K
Developer Profile

Google Plus Authorship Developer Profile

mlazarov

10 plugins · 2K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Google Plus Authorship

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

HTML Comments
<!--tr><!--/tr//-->
Data Attributes
title="Google Plus Profile for +"plugin="Google Plus Authorship"for="gplusauthor"name="gplus_author_url"id="gplus_author_url"value+3 more
Shortcode Output
<a href="" rel="author" title="Google Plus Profile for +" plugin="Google Plus Authorship"
FAQ

Frequently Asked Questions about Google Plus Authorship