
Simply Change Author URL Security & Risk Analysis
wordpress.org/plugins/simply-change-author-urlChanges wordpress user slug for security, it prevents access to the usernames of registered users on your site.
Is Simply Change Author URL Safe to Use in 2026?
Generally Safe
Score 85/100Simply Change Author URL has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "simply-change-author-url" v1.1.2 plugin exhibits a strong security posture based on the provided static analysis. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, significantly reducing the plugin's attack surface. The code also demonstrates good practices by not utilizing dangerous functions, employing prepared statements for all SQL queries, and properly escaping all output. Furthermore, the absence of file operations, external HTTP requests, and the lack of specific code signals for nonce or capability checks (while not ideal, their absence is mitigated by the minimal attack surface) suggest a focus on secure coding. The plugin also has no recorded vulnerability history, which is a positive indicator of its stability and security over time.
While the static analysis indicates a very secure implementation, the complete absence of capability checks and nonce checks, even with a minimal attack surface, represents a potential area for improvement. If the plugin's functionality were to expand or interact with user-specific data in the future, these checks would become critical. The taint analysis showing zero flows with unsanitized paths is excellent, confirming no direct vulnerabilities were detected in how data moves through the code. Overall, the plugin is well-secured against common vulnerabilities based on this data, with only minor areas for theoretical enhancement in more complex scenarios.
Key Concerns
- Missing capability checks
- Missing nonce checks
Simply Change Author URL Security Vulnerabilities
Simply Change Author URL Code Analysis
Output Escaping
Simply Change Author URL Attack Surface
WordPress Hooks 10
Maintenance & Trust
Simply Change Author URL Maintenance & Trust
Maintenance Signals
Community Trust
Simply Change Author URL Alternatives
Edit Author Slug
edit-author-slug
Allows an admin (or capable user) to edit the author slug of a user, and change the author base.
Restrict Usernames Emails Characters
restrict-usernames-emails-characters
Restrict the usernames, email addresses, characters and symbols or email from specific domain names or language in registration ...
WP Author Slug
wp-author-slug
Add a layer of security and prevent your login name from being shown in the author archive's URL.
Keyring
keyring
An authentication framework that handles authorization/communication with most popular web services.
SF Author Url Control
sf-author-url-control
Allows administrators or capable users to change the users profile url.
Simply Change Author URL Developer Profile
1 plugin · 40 total installs
How We Detect Simply Change Author URL
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
<!-- change author base via this filter -->/wp/v2/users/wp/v2/users/(?P[\d]+)/wp/v2/users/me