Simple Blog Authors Widget Security & Risk Analysis

wordpress.org/plugins/simple-blog-authors-widget

This plugin lets provides a simple widget to list your blog's authors, including gravatar and post counts

80 active installs v1.5.1 PHP + WP 2.8+ Updated Apr 24, 2016
authorsblog-authorssimplewidgetwidgets
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Simple Blog Authors Widget Safe to Use in 2026?

Generally Safe

Score 85/100

Simple Blog Authors Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The "simple-blog-authors-widget" v1.5.1 plugin presents a generally positive security posture, with no recorded vulnerabilities or CVEs, and a clean taint analysis indicating no critical or high-severity flows were detected. The absence of dangerous functions, file operations, and external HTTP requests are strong indicators of good coding practices. However, a significant concern arises from the low percentage (15%) of properly escaped output. This suggests a considerable risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected into the site through the plugin's output. The lack of any capability checks or nonce checks on its entry points, although there are currently none, is a potential weakness if new entry points are added in the future without proper authorization mechanisms. While the plugin is currently free from known exploits and exhibits good practices in many areas, the unescaped output remains a notable weakness that requires attention.

Key Concerns

  • Low percentage of properly escaped output
  • No capability checks on entry points
  • No nonce checks on entry points
Vulnerabilities
None known

Simple Blog Authors Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Simple Blog Authors Widget Release Timeline

v1.5.1Current
v1.5.0
v1.4.0
v1.0.3
v1.0.2
v1.0.1
Code Analysis
Analyzed Mar 16, 2026

Simple Blog Authors Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
23
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

15% escaped27 total outputs
Attack Surface

Simple Blog Authors Widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionwidgets_initsimple-blog-authors-widget.php:39
actionwp_enqueue_scriptssimple-blog-authors-widget.php:42
actionplugins_loadedsimple-blog-authors-widget.php:45
Maintenance & Trust

Simple Blog Authors Widget Maintenance & Trust

Maintenance Signals

WordPress version tested4.5.33
Last updatedApr 24, 2016
PHP min version
Downloads21K

Community Trust

Rating0/100
Number of ratings0
Active installs80
Developer Profile

Simple Blog Authors Widget Developer Profile

Stanko Metodiev

3 plugins · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Simple Blog Authors Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/simple-blog-authors-widget/js/main.js
Script Paths
/wp-content/plugins/simple-blog-authors-widget/js/main.js

HTML / DOM Fingerprints

CSS Classes
sbaw_authorssbaw_author
Data Attributes
id="sbaw-select"
JS Globals
sbawAjax
FAQ

Frequently Asked Questions about Simple Blog Authors Widget