
WP About Author Security & Risk Analysis
wordpress.org/plugins/wp-about-authorEasily display customizable author bios below your posts
Is WP About Author Safe to Use in 2026?
Generally Safe
Score 99/100WP About Author has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The wp-about-author plugin v1.6.3 exhibits a generally strong security posture based on the provided static analysis. The plugin has no identified AJAX handlers or REST API routes without authentication, and all SQL queries utilize prepared statements. A significant majority of output is properly escaped, and there are no observed dangerous functions, file operations, or external HTTP requests. The presence of a nonce check is also a positive indicator of security consciousness. However, the vulnerability history reveals one known medium severity CVE related to Cross-Site Scripting (XSS), which was patched according to the data. While this specific version has no outstanding vulnerabilities, the past XSS issue indicates a potential for input sanitization weaknesses that should be monitored in future updates.
Overall, the plugin demonstrates good development practices for securing its entry points and database interactions. The primary concern stems from past vulnerability trends. The absence of capability checks on the single shortcode is a minor oversight, though the lack of unprotected entry points mitigates immediate risk. The total absence of taint analysis results is unusual and could imply either a very small codebase or a limitation in the analysis tool's ability to detect flows in this specific context. Given the past XSS, further scrutiny of input handling is recommended.
Key Concerns
- Past medium severity XSS vulnerability
- No capability checks on shortcode
WP About Author Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WP About Author <= 1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
WP About Author Release Timeline
WP About Author Code Analysis
Output Escaping
WP About Author Attack Surface
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
WP About Author Maintenance & Trust
Maintenance Signals
Community Trust
WP About Author Alternatives
Simple Author Box
simple-author-box
Add a responsive author box or guest author box with social icons to any post. Great author box for any site!
Molongui Authorship – Author Boxes, Guest Authors & Co-Authors for WordPress
molongui-authorship
All-in-One Authorship Solution: Seamless Author Box, Guest Authors, and Co-Authors to enhance your site's authority, credibility, engagement, and SEO.
Starbox – the Author Box for Humans
starbox
Starbox is the Author Box for Humans. Professional Themes to choose from, HTML5, Social Media Profiles, Google Authorship
WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars
wp-post-author
WP Post Author is the ultimate solution for an Author Box, Multiple Authors, Guest Authors, and Local Avatars. Easily manage Author Bios, Co-authors, …
Author Box WP Lens
author-box-for-divi
A plugin which provides an author box for your WordPress blog. Originally known as "Author Box for Divi."
WP About Author Developer Profile
7 plugins · 4K total installs
How We Detect WP About Author
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-about-author/wp-about-author.css/wp-content/plugins/wp-about-author/wp-about-author.js/wp-content/plugins/wp-about-author/wp-about-author.jswp-about-author/wp-about-author.css?ver=wp-about-author/wp-about-author.js?ver=HTML / DOM Fingerprints
wp-about-author-containerwp-about-author-picwp-about-author-circlewp-about-author-pic-bgwp-about-author-textwp-about-author-layout-wp-about-author-container-contact-svgs+1 morewp_author_avatar_sizewp_author_social_imageswp_author_alert_borderlayoutwp_author_alert_bg