
Kento Top Author Security & Risk Analysis
wordpress.org/plugins/kento-top-authorsTop Author list By Count Post
Is Kento Top Author Safe to Use in 2026?
Generally Safe
Score 85/100Kento Top Author has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'kento-top-authors' plugin version 1.0 exhibits a mixed security posture. On one hand, it demonstrates strong security practices by avoiding dangerous functions, implementing prepared statements for all SQL queries, and having no recorded vulnerabilities or CVEs. The attack surface also appears minimal, with no AJAX handlers, REST API routes, shortcodes, or cron events, suggesting a limited scope for direct attack vectors.
However, a significant concern arises from the complete lack of output escaping. With 12 total outputs analyzed and 0% properly escaped, this presents a clear risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data, if not meticulously handled by the WordPress core or theme before reaching these output points, could be injected and executed in the browser of other users. Additionally, the taint analysis reveals 2 flows with unsanitized paths, indicating potential issues where data could be processed in an unsafe manner, although no critical or high severity was assigned, suggesting these might be lower-impact but still noteworthy.
The absence of capability checks and nonce checks in any of the analyzed code segments is also a concern, particularly if any of the plugin's functionalities, even those not directly exposed as AJAX or REST endpoints, could be triggered in a way that modifies data or performs sensitive actions. The vulnerability history being clean is a positive indicator, but it doesn't negate the identified code-level weaknesses that could be exploited.
Key Concerns
- Unescaped output
- Taint flow with unsanitized path
- Missing capability checks
- Missing nonce checks
Kento Top Author Security Vulnerabilities
Kento Top Author Code Analysis
Output Escaping
Data Flow Analysis
Kento Top Author Attack Surface
WordPress Hooks 1
Maintenance & Trust
Kento Top Author Maintenance & Trust
Maintenance Signals
Community Trust
Kento Top Author Alternatives
Author List
author-list
Display the list of authors with gravatar image and show the total number of post count on hover
Author List
author-role-list
Create a Page for users with their roles. With this plugin, you can create different pages as per its user role. This plugin is applicable to any of t …
E20R Better Members List for Paid Memberships Pro
e20r-members-list
Extensible, sortable & bulk action capable members listing + export to CSV tool for Paid Memberships Pro.
List-all-authors
list-all-authors
Das Plugin ermoeglicht die Auflistung aller Authoren, auch solcher, die noch keine Artikel geschrieben haben. The plugin lets you lists all authors, even those without posts.
Popular Authors
popular-authors
Discover and appreciate your blog’s most popular authors, a simple and powerful addon for Top 10 - Popular Posts for WordPress.
Kento Top Author Developer Profile
20 plugins · 600 total installs
How We Detect Kento Top Author
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/kento-top-authors/css/style.cssHTML / DOM Fingerprints
top-authorstop-authors-listtop-authors-imagetop-authors-nametop-authors-postname="widgettitle"name="number"name="kta_style"name="submitted"