
SF Author Url Control Security & Risk Analysis
wordpress.org/plugins/sf-author-url-controlAllows administrators or capable users to change the users profile url.
Is SF Author Url Control Safe to Use in 2026?
Generally Safe
Score 85/100SF Author Url Control has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "sf-author-url-control" plugin v1.2 demonstrates a strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with exposed attack surfaces significantly limits potential entry points for attackers. The code analysis also shows good practices with 100% of SQL queries using prepared statements and a reasonable rate of output escaping (76%). Furthermore, the presence of nonce and capability checks, even with a relatively small number of flows analyzed, indicates a conscious effort to implement basic security measures. The plugin's vulnerability history is entirely clean, with no recorded CVEs, which is a significant positive indicator of its security over time.
While the overall picture is positive, the taint analysis does reveal two flows with unsanitized paths. Although these did not escalate to critical or high severity in this specific analysis, unsanitized paths can still lead to issues if they interact with other parts of the application or if the context of their use is not fully understood. The 76% output escaping, while good, implies that 24% of outputs are not properly escaped, which could potentially lead to cross-site scripting (XSS) vulnerabilities in specific scenarios. These are minor concerns in the context of the plugin's overall security, but they represent areas where further scrutiny might be beneficial.
In conclusion, "sf-author-url-control" v1.2 appears to be a securely developed plugin with no known vulnerabilities and good security practices implemented. The limited attack surface, secure SQL handling, and history of no CVEs are significant strengths. The minor concerns regarding unsanitized paths and a small percentage of unescaped outputs do not detract significantly from its generally strong security profile.
Key Concerns
- Flows with unsanitized paths
- Unescaped output percentage (24%)
SF Author Url Control Security Vulnerabilities
SF Author Url Control Code Analysis
Output Escaping
Data Flow Analysis
SF Author Url Control Attack Surface
WordPress Hooks 14
Maintenance & Trust
SF Author Url Control Maintenance & Trust
Maintenance Signals
Community Trust
SF Author Url Control Alternatives
Remove CPT base
remove-cpt-base
Remove custom post type base slug from url
Custom Permalinks for Custom Post Types
custom-permalinks-for-custom-post-types
Remove base slug of Custom Post Types and change the permalink structure of Custom Post Types.
Simply Change Author URL
simply-change-author-url
Changes wordpress user slug for security, it prevents access to the usernames of registered users on your site.
SLUG TRANSLATER
slug-translater
Translate the slug generated in Japanese into English and replace it with an appropriate format.
All in one demo Export/Import
all-in-one-demo-importexport
Easily export or import your WordPress customizer settings!
SF Author Url Control Developer Profile
5 plugins · 7K total installs
How We Detect SF Author Url Control
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sf-author-url-control/inc/admin.js/wp-content/plugins/sf-author-url-control/css/admin.css/wp-content/plugins/sf-author-url-control/inc/admin.jssf-author-url-control/inc/admin.js?ver=sf-author-url-control/css/admin.css?ver=