Post Author Filter Security & Risk Analysis

wordpress.org/plugins/post-author-filter

Add a author selection on post / page editpage

100 active installs v0.2 PHP + WP 3.0+ Updated Sep 13, 2014
authoreditpagefilterpagepost
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Post Author Filter Safe to Use in 2026?

Generally Safe

Score 85/100

Post Author Filter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The static analysis of the 'post-author-filter' v0.2 plugin reveals a remarkably clean codebase with no identified attack surface entry points, dangerous functions, file operations, or external HTTP requests. Furthermore, all SQL queries are prepared, and output is properly escaped, indicating adherence to fundamental secure coding practices in these areas. The absence of any recorded vulnerabilities, CVEs, or common vulnerability types in its history suggests a low likelihood of known exploits affecting this plugin.

However, a significant concern arises from the complete lack of nonce checks and capability checks. While the current version reports zero unprotected entry points, this absence of proper authorization and validation mechanisms creates a latent risk. If new functionality is introduced in future versions that does not include these checks, or if an unknown entry point is discovered, the plugin could become highly vulnerable to unauthorized actions or privilege escalation attacks. The plugin's strength lies in its current minimal footprint and robust data handling, but its reliance on the absence of exposure points for security is a notable weakness.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Post Author Filter Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Post Author Filter Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Post Author Filter Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionplugins_loadedclass-post-author-filter.php:39
filterrestrict_manage_postsclass-post-author-filter.php:40
Maintenance & Trust

Post Author Filter Maintenance & Trust

Maintenance Signals

WordPress version tested4.0.38
Last updatedSep 13, 2014
PHP min version
Downloads4K

Community Trust

Rating76/100
Number of ratings6
Active installs100
Developer Profile

Post Author Filter Developer Profile

Frank Neumann-Staude

11 plugins · 8K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Post Author Filter

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/post-author-filter/post-author-filter.php/wp-content/plugins/post-author-filter/class-post-author-filter.php

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Post Author Filter