
Visual Authors Page Security & Risk Analysis
wordpress.org/plugins/visual-authors-pageThis "Visual Authors page" plugin display authors list in any page by placing shortcode on it.
Is Visual Authors Page Safe to Use in 2026?
Generally Safe
Score 85/100Visual Authors Page has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "visual-authors-page" v1.0 plugin exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, SQL injection vulnerabilities, file operations, and external HTTP requests is commendable. The fact that all SQL queries use prepared statements and all output is properly escaped demonstrates good development practices for preventing common web vulnerabilities. Furthermore, the lack of any recorded vulnerabilities in its history is a positive indicator, suggesting a well-maintained codebase.
However, the analysis reveals a few areas that could be improved. The most significant concern is the complete absence of nonce checks and capability checks. While the current entry points are limited, this omission leaves the plugin susceptible to cross-site request forgery (CSRF) attacks and unauthorized privilege escalation if new entry points are added or existing ones are modified in the future without proper security measures. The presence of a shortcode, while not directly flagged as vulnerable, represents a potential avenue for attack if it were to process user-supplied data without adequate sanitization or validation, though the taint analysis currently shows no issues.
In conclusion, the plugin is in a relatively secure state due to its clean code and lack of historical vulnerabilities. Nevertheless, the missing nonce and capability checks are critical security oversights that need immediate attention to ensure robust protection against various attack vectors. Addressing these omissions would elevate the plugin's security to an excellent level.
Key Concerns
- Missing nonce checks
- Missing capability checks
Visual Authors Page Security Vulnerabilities
Visual Authors Page Code Analysis
Output Escaping
Visual Authors Page Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
Visual Authors Page Maintenance & Trust
Maintenance Signals
Community Trust
Visual Authors Page Alternatives
Reduce HTTP Requests, Disable Emojis & Disable Embeds, Speedup WooCommerce
wp-disable
Reduce HTTP requests - Disable Emojis, Disable Gravatars, Disable Embeds and Remove Querystrings. SpeedUp WooCommerce, Added support to disable pingba …
Avatar Manager
avatar-manager
Avatar Manager for WordPress is a sweet and simple plugin for storing avatars locally and more. Easily.
Ultimate Post List
ultimate-post-list
Make up custom-tailored preview lists of the contents easily and place them in widget areas and post contents.
Users Registration Date
users-registered-list
New sortable "Registered" date column on the Users page in wp-admin area to see when each user has registered on a site.
WP First Letter Avatar
wp-first-letter-avatar
Set custom avatars for users with no Gravatar. The avatar will be the first (or any other) letter of user's name on a colorful background.
Visual Authors Page Developer Profile
1 plugin · 10 total installs
How We Detect Visual Authors Page
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/visual-authors-page/css/style.css/wp-content/plugins/visual-authors-page/js/admin.js/wp-content/plugins/visual-authors-page/js/admin.jsvisual-authors-page/js/admin.js?ver=visual-authors-page/css/style.css?ver=HTML / DOM Fingerprints
vauthorsvauthor-entryvauthor-datavauthor-post-countervauthor-bioid="vauthors"[vauthors_page][vauthors_page roles=[vauthors_page authors=[vauthors_page counter=