
WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars Security & Risk Analysis
wordpress.org/plugins/wp-post-authorWP Post Author is the ultimate solution for an Author Box, Multiple Authors, Guest Authors, and Local Avatars. Easily manage Author Bios, Co-authors, …
Is WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars Safe to Use in 2026?
Generally Safe
Score 92/100WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "wp-post-author" plugin v3.8.7 exhibits a mixed security posture. While it demonstrates good practices such as a high percentage of prepared SQL statements and properly escaped output, significant concerns remain regarding its attack surface and past vulnerability history. The presence of three AJAX handlers without authentication checks represents a notable risk, as these could be exploited by unauthenticated users to perform unintended actions. Although the static analysis did not reveal any critical taint flows, the plugin's history of six known CVEs, including one critical and one high severity vulnerability, is a significant red flag. The common vulnerability types (SQL Injection, XSS, Missing Authorization, Privilege Management) indicate recurring weaknesses in input sanitization, authorization checks, and privilege handling. This history, combined with the unprotected AJAX endpoints, suggests a pattern of potential security oversights that require careful attention.
Key Concerns
- Unprotected AJAX handlers found
- High number of past CVEs (6 total)
- Past critical severity CVE found
- Past high severity CVE found
- Bundled library (Freemius) outdated (v1.0)
WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars Security Vulnerabilities
CVEs by Year
Severity Breakdown
6 total CVEs
WP Post Author <= 3.8.2 - Authenticated (Administrator+) SQL Injection
Boost Your Blog's Engagement with WP Post Author <= 3.8.1 - Authenticated (Administrator+) SQL Injection
WP Post Author <= 3.6.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
WP Post Author – Enhance Your Posts with the Author Bio, Co-Authors, Guest Authors, and Post Rating System, including User Registration Form Builder <= 3.6.4 - Missing Authorization to Rating Manipulation
WP Post Author – Enhance Your Posts with the Author Bio, Co-Authors, Guest Authors, and Post Rating System, including User Registration Form Builder <= 3.7.4 - Missing Authorization
WP Post Author <= 3.2.3 - Privilege Escalation
WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars Release Timeline
WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars Attack Surface
AJAX Handlers 3
Shortcodes 4
WordPress Hooks 49
Maintenance & Trust
WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars Maintenance & Trust
Maintenance Signals
Community Trust
WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars Alternatives
Simple Author Box
simple-author-box
Add a responsive author box or guest author box with social icons to any post. Great author box for any site!
Molongui Authorship – Author Boxes, Guest Authors & Co-Authors for WordPress
molongui-authorship
All-in-One Authorship Solution: Seamless Author Box, Guest Authors, and Co-Authors to enhance your site's authority, credibility, engagement, and SEO.
Authorsy – Author Box, Multiple Authors, Guest Authors & Post Rating
authorsy
Authorsy is a powerful WordPress author box plugin. Add customizable author profiles, multiple authors, guest authors, bios, social links, and post ra …
Smart Author Box Widget
smart-author-box-widget
Smart Author Box Widget displays author bio box with an image, description, and social links—perfect for multi-author blogs and personal sites.
Meta Author Box
meta-author-box
Add a responsive custom author box. Great author box for any site!
WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars Developer Profile
64 plugins · 95K total installs
How We Detect WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-post-author/assets/css/awpa-backend-style.css/wp-content/plugins/wp-post-author/assets/dist/blocks.build.js/wp-content/plugins/wp-post-author/assets/dist/blocks.build.jswp-post-author/assets/css/awpa-backend-style.css?ver=wp-post-author/assets/dist/blocks.build.js?ver=HTML / DOM Fingerprints
awpa-form-builder-containerdata-srcUrldata-rest_urldata-imgdata-pluginDirdata-all_pageswpauthor_globals