WP Author Profile Box Lite Security & Risk Analysis

wordpress.org/plugins/wp-author-profile-box-lite

WP Author Profile Box Lite is an easy way to highlight author of your WordPress posts.

20 active installs v1.0.2 PHP + WP 3.0.1+ Updated Unknown
author-boxauthor-profile-fieldsauthor-social-iconsprofile-fieldsresponsive-author-box
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Author Profile Box Lite Safe to Use in 2026?

Generally Safe

Score 100/100

WP Author Profile Box Lite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The static analysis of wp-author-profile-box-lite v1.0.2 reveals a generally strong security posture with no identified critical or high-severity vulnerabilities. The plugin demonstrates good practices by utilizing prepared statements for all SQL queries and has a capability check in place. The absence of dangerous functions, file operations, external HTTP requests, and a clean taint analysis further reinforces this positive assessment.

However, there are a couple of areas that warrant attention. The output escaping is only 78% proper, meaning a small percentage of outputs could potentially be vulnerable to cross-site scripting (XSS) if user-supplied data is not handled carefully. Additionally, the plugin bundles the Select2 library, and while no specific vulnerabilities are listed for this version, outdated bundled libraries can sometimes represent a hidden risk if they contain known, unpatched vulnerabilities that are not tracked by the plugin's own vulnerability history.

Given the lack of historical vulnerabilities and the minimal issues found in static analysis, the plugin appears to be well-maintained and secure. The main concern lies with the minor output escaping deficiency and the potential for issues with the bundled library. Addressing these points would further enhance the plugin's security.

Key Concerns

  • Output escaping is not 100% proper
  • Bundled Select2 library may be outdated
Vulnerabilities
None known

WP Author Profile Box Lite Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP Author Profile Box Lite Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
7 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

78% escaped9 total outputs
Attack Surface

WP Author Profile Box Lite Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actionshow_user_profileadmin\class-wp-author-profile-box-lite-admin-view.php:40
actionedit_user_profileadmin\class-wp-author-profile-box-lite-admin-view.php:41
actionpersonal_options_updateadmin\class-wp-author-profile-box-lite-admin-view.php:42
actionedit_user_profile_updateadmin\class-wp-author-profile-box-lite-admin-view.php:43
actionplugins_loadedadmin\class-wp-author-profile-box-lite-admin-view.php:131
actionplugins_loadedincludes\class-wp-author-profile-box-lite.php:143
actionadmin_enqueue_scriptsincludes\class-wp-author-profile-box-lite.php:158
actionadmin_enqueue_scriptsincludes\class-wp-author-profile-box-lite.php:159
actionwp_enqueue_scriptsincludes\class-wp-author-profile-box-lite.php:174
actionwp_enqueue_scriptsincludes\class-wp-author-profile-box-lite.php:175
actiontemplate_redirectpublic\class-wp-author-profile-box-lite-public-view.php:21
actionplugins_loadedpublic\class-wp-author-profile-box-lite-public-view.php:129
Maintenance & Trust

WP Author Profile Box Lite Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.13
Last updatedUnknown
PHP min version
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

WP Author Profile Box Lite Developer Profile

WEN Solutions

47 plugins · 26K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
112 days
View full developer profile
Detection Fingerprints

How We Detect WP Author Profile Box Lite

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-author-profile-box-lite/admin/css/wp-author-profile-box-lite-admin.css/wp-content/plugins/wp-author-profile-box-lite/admin/css/select2.css/wp-content/plugins/wp-author-profile-box-lite/admin/js/wp-author-profile-box-lite-admin.js/wp-content/plugins/wp-author-profile-box-lite/admin/js/select2.js
Script Paths
/wp-content/plugins/wp-author-profile-box-lite/admin/js/wp-author-profile-box-lite-admin.js/wp-content/plugins/wp-author-profile-box-lite/admin/js/select2.js
Version Parameters
wp-author-profile-box-lite-admin.css?ver=wp-author-profile-box-lite-admin.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about WP Author Profile Box Lite