SF Author Url Control Security & Risk Analysis

wordpress.org/plugins/sf-author-url-control

Allows administrators or capable users to change the users profile url.

1K active installs v1.2 PHP + WP 3.0+ Updated Apr 3, 2016
authorcustomcustomizepermalinkslug
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is SF Author Url Control Safe to Use in 2026?

Generally Safe

Score 85/100

SF Author Url Control has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The "sf-author-url-control" plugin v1.2 demonstrates a strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with exposed attack surfaces significantly limits potential entry points for attackers. The code analysis also shows good practices with 100% of SQL queries using prepared statements and a reasonable rate of output escaping (76%). Furthermore, the presence of nonce and capability checks, even with a relatively small number of flows analyzed, indicates a conscious effort to implement basic security measures. The plugin's vulnerability history is entirely clean, with no recorded CVEs, which is a significant positive indicator of its security over time.

While the overall picture is positive, the taint analysis does reveal two flows with unsanitized paths. Although these did not escalate to critical or high severity in this specific analysis, unsanitized paths can still lead to issues if they interact with other parts of the application or if the context of their use is not fully understood. The 76% output escaping, while good, implies that 24% of outputs are not properly escaped, which could potentially lead to cross-site scripting (XSS) vulnerabilities in specific scenarios. These are minor concerns in the context of the plugin's overall security, but they represent areas where further scrutiny might be beneficial.

In conclusion, "sf-author-url-control" v1.2 appears to be a securely developed plugin with no known vulnerabilities and good security practices implemented. The limited attack surface, secure SQL handling, and history of no CVEs are significant strengths. The minor concerns regarding unsanitized paths and a small percentage of unescaped outputs do not detract significantly from its generally strong security profile.

Key Concerns

  • Flows with unsanitized paths
  • Unescaped output percentage (24%)
Vulnerabilities
None known

SF Author Url Control Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

SF Author Url Control Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
16 escaped
Nonce Checks
2
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

76% escaped21 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
sf_auc_save_author_base (inc\admin.php:198)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

SF Author Url Control Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 14
actioninitinc\admin.php:49
actionadmin_noticesinc\admin.php:73
filtermanage_users_columnsinc\admin.php:103
filtermanage_users_custom_columninc\admin.php:113
actionadmin_print_scripts-users.phpinc\admin.php:138
actionload-options-permalink.phpinc\admin.php:151
actionload-options-permalink.phpinc\admin.php:196
actionshow_user_profileinc\admin.php:292
actionedit_user_profileinc\admin.php:293
actionpersonal_options_updateinc\admin.php:329
actionedit_user_profile_updateinc\admin.php:330
actionuser_profile_update_errorsinc\admin.php:359
actionuser_profile_update_errorsinc\admin.php:362
actioninitsf-author-url-control.php:42
Maintenance & Trust

SF Author Url Control Maintenance & Trust

Maintenance Signals

WordPress version tested4.5.33
Last updatedApr 3, 2016
PHP min version
Downloads21K

Community Trust

Rating100/100
Number of ratings11
Active installs1K
Developer Profile

SF Author Url Control Developer Profile

Grégory Viguier

5 plugins · 7K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SF Author Url Control

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sf-author-url-control/inc/admin.js/wp-content/plugins/sf-author-url-control/css/admin.css
Script Paths
/wp-content/plugins/sf-author-url-control/inc/admin.js
Version Parameters
sf-author-url-control/inc/admin.js?ver=sf-author-url-control/css/admin.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about SF Author Url Control