
Cool Author Box – For Widget and Post Content Security & Risk Analysis
wordpress.org/plugins/hm-cool-author-box-widgetCool Author Box displays an responsive author box with social media links to your widget and post content area.
Is Cool Author Box – For Widget and Post Content Safe to Use in 2026?
Generally Safe
Score 99/100Cool Author Box – For Widget and Post Content has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "hm-cool-author-box-widget" plugin v3.0.3 exhibits a mixed security posture. While it demonstrates good practices such as using prepared statements for all SQL queries and a reasonable number of nonce and capability checks, significant concerns arise from its attack surface and output escaping. Two AJAX handlers are exposed without authentication checks, creating a direct entry point for potential unauthorized actions. Furthermore, only 51% of output is properly escaped, suggesting a risk of Cross-Site Scripting (XSS) vulnerabilities in its rendering functions. The plugin's vulnerability history, including two previously disclosed medium-severity vulnerabilities related to CSRF and Missing Authorization, reinforces the concerns identified in the static analysis. Although no critical or high vulnerabilities are currently active, and the most recent vulnerability was in the past, the pattern of past issues highlights a need for continued vigilance. The presence of the Freemius v1.0 bundled library also warrants consideration for potential outdated components.
Key Concerns
- Unprotected AJAX handlers
- Low percentage of properly escaped output
- Bundled outdated library (Freemius v1.0)
- Previous medium severity vulnerabilities (CSRF, Missing Auth)
Cool Author Box – For Widget and Post Content Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Cool Author Box <= 3.0.0 - Cross-Site Request Forgery
Cool Author Box <= 2.9.9 - Missing Authorization
Cool Author Box – For Widget and Post Content Release Timeline
Cool Author Box – For Widget and Post Content Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Cool Author Box – For Widget and Post Content Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 14
Maintenance & Trust
Cool Author Box – For Widget and Post Content Maintenance & Trust
Maintenance Signals
Community Trust
Cool Author Box – For Widget and Post Content Alternatives
Simple Author Box
simple-author-box
Add a responsive author box or guest author box with social icons to any post. Great author box for any site!
Smart Author Box Widget
smart-author-box-widget
Smart Author Box Widget displays author bio box with an image, description, and social links—perfect for multi-author blogs and personal sites.
Magic Author Box
magic-author-box
Display responsive customized author box with social icons on posts. Fully customizable templates for each author with separate UI design.
Author Box WP Lens
author-box-for-divi
A plugin which provides an author box for your WordPress blog. Originally known as "Author Box for Divi."
Authorsy – Author Box, Multiple Authors, Guest Authors & Post Rating
authorsy
Authorsy is a powerful WordPress author box plugin. Add customizable author profiles, multiple authors, guest authors, bios, social links, and post ra …
Cool Author Box – For Widget and Post Content Developer Profile
14 plugins · 8K total installs
How We Detect Cool Author Box – For Widget and Post Content
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/hm-cool-author-box-widget/assets/css/fontawesome/css/all.min.css/wp-content/plugins/hm-cool-author-box-widget/assets/css/hmcab--admin.css/wp-content/plugins/hm-cool-author-box-widget/assets/js/hmcab--admin.js/wp-content/plugins/hm-cool-author-box-widget/assets/css/fontawesome/css/all.min.css/wp-content/plugins/hm-cool-author-box-widget/assets/css/hmcab--admin.css/wp-content/plugins/hm-cool-author-box-widget/assets/js/hmcab--admin.jshm-cool-author-box-widget/assets/css/fontawesome/css/all.min.css?ver=hm-cool-author-box-widget/assets/css/hmcab--admin.css?ver=hm-cool-author-box-widget/assets/js/hmcab--admin.js?ver=HTML / DOM Fingerprints
hmcab-author-box-containerhmcab-social-icons<!-- Cool Author Box Widget -->data-hmcab-settingsHMCABW_PATHHMCABW_ASSETSHMCABW_LANGHMCABW_SLUGHMCABW_PREFIXHMCABW_CLASSPREFIX+2 more[hm_cool_author_box]