
People Page Security & Risk Analysis
wordpress.org/plugins/people-pageCreate a "People Page" that displays a list of selected site users with photos, bios, titles, links and more.
Is People Page Safe to Use in 2026?
Generally Safe
Score 85/100People Page has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'people-page' plugin v1.1 exhibits a generally good security posture, with several positive indicators. Notably, all identified entry points (1 AJAX handler) have associated authorization checks. The absence of REST API routes, shortcodes, and cron events contributes to a minimal attack surface. Furthermore, all SQL queries are executed using prepared statements, which is a critical security practice. The plugin also demonstrates good practice by incorporating nonce and capability checks. However, a significant concern arises from the presence of the `create_function` dangerous function, which can lead to code injection vulnerabilities if not handled with extreme caution. Additionally, the output escaping is only 48% proper, indicating a substantial risk of Cross-Site Scripting (XSS) vulnerabilities in the remaining 52% of outputs. The plugin has no recorded vulnerabilities, which is a strong positive sign, suggesting a proactive approach to security or a lack of past discovered issues.
Key Concerns
- Presence of dangerous function create_function
- Low percentage of properly escaped output
People Page Security Vulnerabilities
People Page Code Analysis
Dangerous Functions Found
Output Escaping
People Page Attack Surface
AJAX Handlers 1
WordPress Hooks 9
Maintenance & Trust
People Page Maintenance & Trust
Maintenance Signals
Community Trust
People Page Alternatives
Simple Local Avatars
simple-local-avatars
Adds an avatar upload field to user profiles. Generates requested sizes on demand just like Gravatar!
Co-Authors Plus
co-authors-plus
Assign multiple bylines to posts, pages, and custom post types with a search-as-you-type input box.
Starbox – the Author Box for Humans
starbox
Starbox is the Author Box for Humans. Professional Themes to choose from, HTML5, Social Media Profiles, Google Authorship
Smart User Slug Hider
smart-user-slug-hider
Hide usernames in Author Pages URLs to enhance Security
User Photo
user-photo
Allows a user to associate a photo with their account and for this photo to be displayed in their posts and comments.
People Page Developer Profile
5 plugins · 150 total installs
How We Detect People Page
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/people-page/style-admin.css/wp-content/plugins/people-page/script-user-edit-upload.js/wp-content/plugins/people-page/script.jsHTML / DOM Fingerprints
people-pagepersonphotouserphotonametitlepostsAndWebsitebracket+11 moreid="people-page"id="author-class="photo"class="photo userphoto"class="name"class="title"+14 more<div id="people-page"<div id="author-<h3 class="name"><div class="title">