
WP Custom Author URL Security & Risk Analysis
wordpress.org/plugins/wp-custom-author-urlSet a custom URL for your author name link, on a global or author-specific basis. Also redirects all author pages.
Is WP Custom Author URL Safe to Use in 2026?
Generally Safe
Score 92/100WP Custom Author URL has a strong security track record. Known vulnerabilities have been patched promptly.
The wp-custom-author-url v2.1.0 plugin exhibits a generally positive security posture with no identified critical or high-severity vulnerabilities in the static analysis or taint analysis phases. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface, which is a strong indication of good development practices. Furthermore, all SQL queries are prepared, and there are no file operations or external HTTP requests, which are all favorable security attributes. The presence of capability checks is also a positive sign for access control.
However, a concern arises from the static analysis indicating that 36% of output is not properly escaped. While there are no reported critical or high-severity vulnerabilities currently, a medium-severity Cross-site Scripting (XSS) vulnerability was patched in April 2023, and the common vulnerability type points to XSS. This suggests that while immediate critical risks are low, there's a historical pattern of output sanitization issues that could be exploited if not diligently addressed in future updates, especially given the unescaped output percentage. The plugin's lack of nonce checks also presents a potential area for improvement to further strengthen its defenses against certain types of attacks.
In conclusion, wp-custom-author-url v2.1.0 benefits from a minimal attack surface and secure handling of database operations. The primary area for improvement lies in ensuring all output is properly escaped to mitigate potential XSS vulnerabilities, especially given its past history. While currently secure, proactive attention to output escaping and potential nonce implementation would enhance its overall security robustness.
Key Concerns
- Medium severity XSS vulnerability (patched)
- 36% of output unescaped
- 0 Nonce checks
WP Custom Author URL Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WP Custom Author URL <= 1.0.4 - Authenticated (Administrator+) Stored Cross-Site Scripting
WP Custom Author URL Code Analysis
Output Escaping
WP Custom Author URL Attack Surface
WordPress Hooks 20
Maintenance & Trust
WP Custom Author URL Maintenance & Trust
Maintenance Signals
Community Trust
WP Custom Author URL Alternatives
Simple Author Box
simple-author-box
Add a responsive author box or guest author box with social icons to any post. Great author box for any site!
Meks Smart Author Widget
meks-smart-author-widget
Easily display your author/user profile info inside WordPress widget.
WP Post Author – Author Box, Co-Authors & Guest Authors
wp-post-author
WP Post Author provides a complete solution for displaying author information, managing multiple authors, collecting post ratings, and creating user r …
Author Avatars List/Block
author-avatars
Display lists of user avatars using widgets or shortcodes. With Gutenberg support.
RS Author Info Box
rs-author-info-box
A simple and lightweight widget to display an author's name, profile image, short description, and social media links in any sidebar or widget area.
WP Custom Author URL Developer Profile
3 plugins · 5K total installs
How We Detect WP Custom Author URL
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-custom-author-url/assets/css/admin-settings.css/wp-content/plugins/wp-custom-author-url/assets/js/admin-settings.js/wp-content/plugins/wp-custom-author-url/assets/js/admin-settings.jswp-custom-author-url/assets/css/admin-settings.css?ver=wp-custom-author-url/assets/js/admin-settings.js?ver=HTML / DOM Fingerprints
<!-- WP Custom Author URL Settings -->data-user-id