
SP Authors Security & Risk Analysis
wordpress.org/plugins/sp-authorsThis very simple plugin allows multiple authors to be assigned to a Post or Page.
Is SP Authors Safe to Use in 2026?
Generally Safe
Score 85/100SP Authors has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "sp-authors" v1.0 plugin exhibits a concerning security posture despite its limited attack surface and lack of recorded vulnerabilities. The static analysis reveals significant weaknesses in core security practices. Notably, all SQL queries are executed without the use of prepared statements, opening the door to SQL injection vulnerabilities. Furthermore, none of the identified output operations are properly escaped, which could lead to cross-site scripting (XSS) flaws if user-supplied data is ever incorporated into these outputs. The absence of nonce checks and capability checks on any potential entry points, though currently few, represents a critical gap in authorization and validation, making the plugin susceptible to unauthorized actions if its attack surface expands or if vulnerabilities are introduced in the future. The clean vulnerability history is a positive indicator, but it does not negate the inherent risks present in the current codebase's insecure coding practices. Without addressing the unescaped output and raw SQL queries, the plugin remains vulnerable, and its security posture should be considered poor.
Key Concerns
- SQL queries do not use prepared statements
- Output escaping is not implemented
- No nonce checks implemented
- No capability checks implemented
SP Authors Security Vulnerabilities
SP Authors Code Analysis
SQL Query Safety
Output Escaping
SP Authors Attack Surface
Shortcodes 1
WordPress Hooks 9
Maintenance & Trust
SP Authors Maintenance & Trust
Maintenance Signals
Community Trust
SP Authors Alternatives
Byline
byline
Solves the co/multi-author problem without modifying the theme. Uses a custom taxonomy, "Byline," that replaces the Display Author.
Co-Authors Widget
widget-for-co-authors
The plugin add a widget and a shortcode in order to show authors of an article. It is compatible with Co-Authors Plus.
Extend Co-Authors Plus for FacetWP
extend-co-authors-plus-for-facetwp
Add an Co-Authors facet to FacetWP
Co-Authors Plus
co-authors-plus
Assign multiple bylines to posts, pages, and custom post types with a search-as-you-type input box.
Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors
publishpress-authors
PublishPress Authors is the best plugin for adding authors, co-authors, multiple authors and guest authors to WordPress posts.
SP Authors Developer Profile
1 plugin · 10 total installs
How We Detect SP Authors
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sp-authors/sp-authors.js/wp-content/plugins/sp-authors/sp-authors.jsHTML / DOM Fingerprints
buttonid="wp-authors-submit"name="_sp_authors"id="_sp_authors"[sp-authors]