RS Author Info Box Security & Risk Analysis

wordpress.org/plugins/rs-author-info-box

A simple and lightweight widget to display an author's name, profile image, short description, and social media links in any sidebar or widget area.

2K active installs v2.2.0 PHP 7.4+ WP 4.9+ Updated Mar 4, 2026
about-me-widgetauthor-profileauthor-widgetbio-widget
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is RS Author Info Box Safe to Use in 2026?

Generally Safe

Score 100/100

RS Author Info Box has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The 'rs-author-info-box' plugin version 2.2.0 exhibits a generally strong security posture based on the provided static analysis. The absence of any identified dangerous functions, unsanitized taint flows, file operations, or external HTTP requests is commendable. Furthermore, the plugin demonstrates excellent practices with 100% of its SQL queries using prepared statements and a very high percentage (99%) of properly escaped output, significantly mitigating risks of SQL injection and cross-site scripting.

However, the analysis reveals a critical area of concern: the complete lack of nonces and capability checks across all identified entry points. While the current attack surface is zero, this indicates a potential for privilege escalation or unauthorized actions if new entry points are introduced or if existing functionalities are exposed without proper authentication and authorization. The absence of any recorded vulnerabilities in its history is a positive sign, suggesting a history of responsible development, but it does not negate the inherent risk posed by the missing security checks.

In conclusion, the plugin scores well on preventing common direct code vulnerabilities. Its strengths lie in its secure handling of database operations and output sanitization. The primary weakness is the foundational lack of nonces and capability checks, which represents a significant risk for future extensibility and potential unintended access if not addressed. This suggests the developers may prioritize direct code security but have overlooked essential WordPress security best practices for user interaction and access control.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

RS Author Info Box Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

RS Author Info Box Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
97 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

99% escaped98 total outputs
Attack Surface

RS Author Info Box Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_footerincludes\author-info-box-widget.php:12
actioncustomize_controls_print_footer_scriptsincludes\author-info-box-widget.php:13
actionwidgets_initincludes\author-info-box-widget.php:329
actionwp_enqueue_scriptsrs-author-info-box.php:30
Maintenance & Trust

RS Author Info Box Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedMar 4, 2026
PHP min version7.4
Downloads28K

Community Trust

Rating0/100
Number of ratings0
Active installs2K
Developer Profile

RS Author Info Box Developer Profile

RS WP THEMES

14 plugins · 6K total installs

92
trust score
Avg Security Score
97/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect RS Author Info Box

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/rs-author-info-box/assets/webfonts/icons.css/wp-content/plugins/rs-author-info-box/assets/css/style.css
Version Parameters
rs-author-info-box/assets/css/style.css?ver=rs-author-info-box/assets/webfonts/icons.css?ver=

HTML / DOM Fingerprints

CSS Classes
rs-author-info-box_author-bio-widgetrs-author-info-box_author-bio-image-wrapperrs-author-info-box_author-bio-image-innerrs-author-info-box_author-bio-contentrs-author-info-box_social_linkrswpthemes-iconicon-facebookicon-twitter+5 more
Data Attributes
data-editor
JS Globals
wp.media
FAQ

Frequently Asked Questions about RS Author Info Box