
WP Author Report Free Security & Risk Analysis
wordpress.org/plugins/wp-author-report-free"WP Author Report" is the only productivity plugin for WordPress which will generate detail report how authors are working.
Is WP Author Report Free Safe to Use in 2026?
Generally Safe
Score 100/100WP Author Report Free has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-author-report-free plugin version 1.0.7 exhibits a mixed security posture. On the positive side, there are no recorded vulnerabilities (CVEs) in its history, and the static analysis reveals no directly exploitable attack vectors like unprotected AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, the absence of dangerous functions, file operations, and external HTTP requests is commendable. However, significant concerns arise from the code analysis. A substantial percentage of SQL queries (73%) are not using prepared statements, posing a high risk of SQL injection. Equally worrying is the very low rate of proper output escaping (5%), indicating a strong likelihood of cross-site scripting (XSS) vulnerabilities. The taint analysis, while limited in scope, did identify two flows with unsanitized paths, suggesting potential for path traversal or other file system related vulnerabilities, though the severity was not classified as critical or high in the static analysis. The plugin also lacks any explicit nonce checks, and only one capability check is present, leaving much of its functionality potentially accessible without proper authorization, especially when combined with the output escaping issues.
Key Concerns
- High percentage of SQL queries not using prepared statements
- Very low percentage of output properly escaped
- Taint analysis shows unsanitized paths
- No nonce checks found
- Minimal capability checks
WP Author Report Free Security Vulnerabilities
WP Author Report Free Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Author Report Free Attack Surface
WordPress Hooks 7
Maintenance & Trust
WP Author Report Free Maintenance & Trust
Maintenance Signals
Community Trust
WP Author Report Free Alternatives
The Paste
the-paste
Paste files and image data from clipboard and instantly upload them to the WordPress media library.
Publish to Schedule
publish-to-schedule
Automate your WordPress post scheduling with Publish to Schedule. Set rules for days and times to publish posts automatically, saving you time and ens …
Admin Page Spider
admin-page-spider
Puts all your pages and posts into the admin bar so you can simply hover, view & edit anything in one click.
Default Post Author
default-post-author
The easiest way to set a default post author in your WordPress site.
Noted!
noted
A simple, lightweight, and user-friendly note-taking system within the WordPress admin.
WP Author Report Free Developer Profile
46 plugins · 4.0M total installs
How We Detect WP Author Report Free
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-author-report-free/css/images/icon.ico/wp-content/plugins/wp-author-report-free/css/images/title-banner-free.png/wp-content/plugins/wp-author-report-free/css/images/header-banner-free-with-price.png/wp-content/plugins/wp-author-report-free/css/images/calendar.gifHTML / DOM Fingerprints
button-primaryreadonly="readonly"