
ThemeRuby Multi Authors – Assign Multiple Writers to Posts Security & Risk Analysis
wordpress.org/plugins/themeruby-multi-authorsA lightweight plugin that allows you to assign multiple writers to posts, fast and easy to use.
Is ThemeRuby Multi Authors – Assign Multiple Writers to Posts Safe to Use in 2026?
Generally Safe
Score 99/100ThemeRuby Multi Authors – Assign Multiple Writers to Posts has a strong security track record. Known vulnerabilities have been patched promptly.
The 'themeruby-multi-authors' plugin version 1.2.0 exhibits a generally strong security posture based on the provided static analysis. The plugin demonstrates good practices by exclusively using prepared statements for SQL queries and properly escaping a high percentage of its outputs. Furthermore, the presence of nonce and capability checks on all identified AJAX handlers is commendable. The absence of direct file operations and external HTTP requests also reduces potential attack vectors. The taint analysis also indicates no critical or high severity issues.
However, the plugin has a history of a medium severity vulnerability, specifically Cross-Site Scripting (XSS). While this specific vulnerability is marked as patched and the last known vulnerability was in the future (which is likely a data anomaly), the presence of past XSS issues suggests that input sanitization and output escaping might require continued vigilance. The fact that the last reported vulnerability was relatively recent (even with the anomalous date) indicates that ongoing maintenance and testing are important for this plugin.
In conclusion, 'themeruby-multi-authors' v1.2.0 appears to be reasonably secure, with robust handling of sensitive operations like database queries and user inputs. The comprehensive checks in place for its entry points are a significant strength. The primary area for continued attention would be the historical trend of XSS vulnerabilities, even though the current version may have addressed this. The plugin's strengths outweigh its weaknesses in this assessment.
Key Concerns
- Past medium severity XSS vulnerability
ThemeRuby Multi Authors – Assign Multiple Writers to Posts Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
ThemeRuby Multi Authors <= 1.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'before' and 'after' Shortcode Attributes
ThemeRuby Multi Authors – Assign Multiple Writers to Posts Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
ThemeRuby Multi Authors – Assign Multiple Writers to Posts Attack Surface
AJAX Handlers 4
Shortcodes 5
WordPress Hooks 32
Maintenance & Trust
ThemeRuby Multi Authors – Assign Multiple Writers to Posts Maintenance & Trust
Maintenance Signals
Community Trust
ThemeRuby Multi Authors – Assign Multiple Writers to Posts Alternatives
Co-Authors Plus
co-authors-plus
Assign multiple bylines to posts, pages, and custom post types with a search-as-you-type input box.
Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors
publishpress-authors
PublishPress Authors is the best plugin for adding authors, co-authors, multiple authors and guest authors to WordPress posts.
Molongui Authorship – Author Boxes, Guest Authors & Co-Authors for WordPress
molongui-authorship
All-in-One Authorship Solution: Seamless Author Box, Guest Authors, and Co-Authors to enhance your site's authority, credibility, engagement, and SEO.
Authorsy – Author Box, Multiple Authors, Guest Authors & Post Rating
authorsy
Authorsy is a powerful WordPress author box plugin. Add customizable author profiles, multiple authors, guest authors, bios, social links, and post ra …
Byline
byline
Solves the co/multi-author problem without modifying the theme. Uses a custom taxonomy, "Byline," that replaces the Display Author.
ThemeRuby Multi Authors – Assign Multiple Writers to Posts Developer Profile
5 plugins · 7K total installs
How We Detect ThemeRuby Multi Authors – Assign Multiple Writers to Posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/themeruby-multi-authors/assets/tma-frontend.css/wp-content/plugins/themeruby-multi-authors/assets/tma-frontend-rtl.cssthemeruby-multi-authors/assets/tma-frontend.css?ver=themeruby-multi-authors/assets/tma-frontend-rtl.css?ver=HTML / DOM Fingerprints
tmauthors-authorsdata-tmauthors-toggletmauthors_admin_ajax_object[themeruby_authors][themeruby_authors_list]