
Co-Authors Widget Security & Risk Analysis
wordpress.org/plugins/widget-for-co-authorsThe plugin add a widget and a shortcode in order to show authors of an article. It is compatible with Co-Authors Plus.
Is Co-Authors Widget Safe to Use in 2026?
Generally Safe
Score 85/100Co-Authors Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The widget-for-co-authors plugin version 0.6 presents a mixed security posture. On the positive side, the plugin demonstrates good practices by avoiding dangerous functions, making all SQL queries using prepared statements, and not performing file operations or external HTTP requests. There are also no known vulnerabilities (CVEs) associated with this version, and the taint analysis revealed no critical or high-severity issues. This suggests a generally robust development approach concerning these areas.
However, significant concerns arise from the lack of security checks on its entry points. The plugin has two shortcodes, and neither the static analysis nor the taint analysis indicate any nonce or capability checks. While the attack surface is small, these unprotected shortcodes represent potential vectors for attack if they can be manipulated to execute unintended actions. Furthermore, the very low percentage of properly escaped output (9%) is a substantial risk. This indicates that data outputted by the plugin is highly likely to be vulnerable to Cross-Site Scripting (XSS) attacks, which could allow attackers to inject malicious scripts into the user's browser.
In conclusion, while the absence of known vulnerabilities and the secure handling of database queries and external interactions are strengths, the critical lack of input sanitization and output escaping, coupled with unprotected shortcodes, creates a significant security risk, primarily for XSS. The plugin's overall security is compromised by these fundamental weaknesses in handling user-supplied data and ensuring secure output.
Key Concerns
- No nonce checks on entry points
- No capability checks on entry points
- Low output escaping percentage (9%)
Co-Authors Widget Security Vulnerabilities
Co-Authors Widget Code Analysis
Output Escaping
Co-Authors Widget Attack Surface
Shortcodes 2
WordPress Hooks 3
Maintenance & Trust
Co-Authors Widget Maintenance & Trust
Maintenance Signals
Community Trust
Co-Authors Widget Alternatives
Byline
byline
Solves the co/multi-author problem without modifying the theme. Uses a custom taxonomy, "Byline," that replaces the Display Author.
Extend Co-Authors Plus for FacetWP
extend-co-authors-plus-for-facetwp
Add an Co-Authors facet to FacetWP
Co-Authors Plus
co-authors-plus
Assign multiple bylines to posts, pages, and custom post types with a search-as-you-type input box.
SP Authors
sp-authors
This very simple plugin allows multiple authors to be assigned to a Post or Page.
Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors
publishpress-authors
PublishPress Authors is the best plugin for adding authors, co-authors, multiple authors and guest authors to WordPress posts.
Co-Authors Widget Developer Profile
1 plugin · 30 total installs
How We Detect Co-Authors Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/widget-for-co-authors/blog-spoiler.csswidget-for-co-authors/blog-spoiler.css?ver=HTML / DOM Fingerprints
block-item-textread-more-stateread-more-wrapread-more-trigger_closedread-more-trigger_openedfor="1"for="2"for="3"for="4"for="5"for="6"+4 more[blog-post-coauthors][blog-coauthors-avatars]