
VK Post Author Display Security & Risk Analysis
wordpress.org/plugins/vk-post-author-displayDisplay to Post Author Information Box on bottom of the contents.
Is VK Post Author Display Safe to Use in 2026?
Generally Safe
Score 100/100VK Post Author Display has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The vk-post-author-display plugin version 1.26.2 exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, SQL queries executed via prepared statements, file operations, and external HTTP requests is commendable. Furthermore, the presence of nonce checks and the limited number of entry points (two shortcodes) contribute to a reduced attack surface. The plugin also has no recorded vulnerability history, which suggests consistent security efforts or a lack of historically exploitable flaws.
However, a primary concern arises from the output escaping. With 84 total outputs and only 74% properly escaped, there's a significant portion (26%) of outputs that are not adequately sanitized. This could potentially lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is rendered directly in the output without proper escaping. While taint analysis showed no unsanitized paths, the unescaped outputs represent a direct risk that needs attention. The lack of capability checks on the identified entry points, though minimal in number, also presents a theoretical risk of unauthorized access or modification if the shortcodes were to process sensitive information.
Key Concerns
- Unescaped output percentage is too high
- No capability checks on entry points
VK Post Author Display Security Vulnerabilities
VK Post Author Display Release Timeline
VK Post Author Display Code Analysis
Output Escaping
VK Post Author Display Attack Surface
Shortcodes 2
WordPress Hooks 16
Maintenance & Trust
VK Post Author Display Maintenance & Trust
Maintenance Signals
Community Trust
VK Post Author Display Alternatives
WP Meta and Date Remover
wp-meta-and-date-remover
Remove meta author and date information from posts and pages. Hide from Humans and Search engines.SEO friendly and most advance plugin.
WP Author, Date and Meta Remover
wp-author-date-and-meta-remover
Don't need the post date and author meta data on your pages? Install WP Author, Date and Meta Remover and its gone. It's that easy!
Guest Author
guest-author
Add a guest author to any post without needing to register the guest author as a user on your site.
Author Category
author-category
simple lightweight plugin limit authors to post just in one category.
Author Filters
author-filters
Author filters plugin integrates an author filter drop down to sort listing on post, page, custom post type in admin.
VK Post Author Display Developer Profile
5 plugins · 218K total installs
How We Detect VK Post Author Display
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/vk-post-author-display/assets/css/vk-post-author.cssvk-post-author-display/assets/css/vk-post-author.css?ver=HTML / DOM Fingerprints
vk_post_author_box<!-- BEGIN VK Post Author Box --><!-- END VK Post Author Box -->data-vk-post-author-box