
WP Post Author – Author Box, Co-Authors & Guest Authors Security & Risk Analysis
wordpress.org/plugins/wp-post-authorWP Post Author provides a complete solution for displaying author information, managing multiple authors, collecting post ratings, and creating user r …
Is WP Post Author – Author Box, Co-Authors & Guest Authors Safe to Use in 2026?
Generally Safe
Score 92/100WP Post Author – Author Box, Co-Authors & Guest Authors has a strong security track record. Known vulnerabilities have been patched promptly.
The "wp-post-author" plugin v3.8.7 exhibits a mixed security posture. While it demonstrates good practices such as a high percentage of prepared SQL statements and properly escaped output, significant concerns remain regarding its attack surface and past vulnerability history. The presence of three AJAX handlers without authentication checks represents a notable risk, as these could be exploited by unauthenticated users to perform unintended actions. Although the static analysis did not reveal any critical taint flows, the plugin's history of six known CVEs, including one critical and one high severity vulnerability, is a significant red flag. The common vulnerability types (SQL Injection, XSS, Missing Authorization, Privilege Management) indicate recurring weaknesses in input sanitization, authorization checks, and privilege handling. This history, combined with the unprotected AJAX endpoints, suggests a pattern of potential security oversights that require careful attention.
Key Concerns
- Unprotected AJAX handlers found
- High number of past CVEs (6 total)
- Past critical severity CVE found
- Past high severity CVE found
- Bundled library (Freemius) outdated (v1.0)
WP Post Author – Author Box, Co-Authors & Guest Authors Security Vulnerabilities
CVEs by Year
Severity Breakdown
6 total CVEs
WP Post Author <= 3.8.2 - Authenticated (Administrator+) SQL Injection
Boost Your Blog's Engagement with WP Post Author <= 3.8.1 - Authenticated (Administrator+) SQL Injection
WP Post Author <= 3.6.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
WP Post Author – Enhance Your Posts with the Author Bio, Co-Authors, Guest Authors, and Post Rating System, including User Registration Form Builder <= 3.6.4 - Missing Authorization to Rating Manipulation
WP Post Author – Enhance Your Posts with the Author Bio, Co-Authors, Guest Authors, and Post Rating System, including User Registration Form Builder <= 3.7.4 - Missing Authorization
WP Post Author <= 3.2.3 - Privilege Escalation
WP Post Author – Author Box, Co-Authors & Guest Authors Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
WP Post Author – Author Box, Co-Authors & Guest Authors Attack Surface
AJAX Handlers 3
Shortcodes 4
WordPress Hooks 49
Maintenance & Trust
WP Post Author – Author Box, Co-Authors & Guest Authors Maintenance & Trust
Maintenance Signals
Community Trust
WP Post Author – Author Box, Co-Authors & Guest Authors Alternatives
Simple Author Box
simple-author-box
Add a responsive author box or guest author box with social icons to any post. Great author box for any site!
Smart Author Box Widget
smart-author-box-widget
Smart Author Box Widget displays author bio box with an image, description, and social links—perfect for multi-author blogs and personal sites.
Authorsy – Author Box, Multiple Authors, Guest Authors & Post Rating
authorsy
Authorsy is a powerful WordPress author box plugin. Add customizable author profiles, multiple authors, guest authors, bios, social links, and post ra …
Cool Author Box – For Widget and Post Content
hm-cool-author-box-widget
Cool Author Box displays an responsive author box with social media links to your widget and post content area.
Magic Author Box
magic-author-box
Display responsive customized author box with social icons on posts. Fully customizable templates for each author with separate UI design.
WP Post Author – Author Box, Co-Authors & Guest Authors Developer Profile
64 plugins · 96K total installs
How We Detect WP Post Author – Author Box, Co-Authors & Guest Authors
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-post-author/assets/css/awpa-backend-style.css/wp-content/plugins/wp-post-author/assets/dist/blocks.build.js/wp-content/plugins/wp-post-author/assets/dist/blocks.build.jswp-post-author/assets/css/awpa-backend-style.css?ver=wp-post-author/assets/dist/blocks.build.js?ver=HTML / DOM Fingerprints
awpa-form-builder-containerdata-srcUrldata-rest_urldata-imgdata-pluginDirdata-all_pageswpauthor_globals