X3P0: Authors Security & Risk Analysis

wordpress.org/plugins/x3p0-authors

A customizable authors list block that lets you showcase post authors, their feed links, and post counts.

40 active installs v2.0.0 PHP 8.1+ WP 6.8+ Updated Feb 23, 2026
authorsblockblocksgutenberglist
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is X3P0: Authors Safe to Use in 2026?

Generally Safe

Score 100/100

X3P0: Authors has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "x3p0-authors" plugin version 2.0.0 demonstrates a strong security posture based on the provided static analysis results. There are no identified critical or high severity code signals such as dangerous functions, unsanitized taint flows, or direct SQL queries. The plugin also avoids common vulnerabilities like external HTTP requests, file operations, and the use of bundled libraries, which often serve as vectors for outdated components. Furthermore, the absence of recorded vulnerabilities in its history suggests a track record of secure development and maintenance.

However, the analysis does highlight some areas for potential concern. The complete lack of nonce checks and capability checks across all entry points, coupled with a notable percentage of output that is not properly escaped, represent weaknesses. While the attack surface appears small and currently without identified unprotected entry points, future additions or changes to the plugin could inadvertently introduce risks if these fundamental security practices are not implemented. The fact that 20% of outputs are not properly escaped could lead to Cross-Site Scripting (XSS) vulnerabilities if the unescaped data is user-supplied or sensitive.

Overall, the plugin is in a good security state due to its clean code signals and lack of historical vulnerabilities. However, the oversight in implementing nonces, capability checks, and robust output escaping on all instances is a notable deficiency that could be exploited. The plugin authors should prioritize addressing these shortcomings to further enhance its security.

Key Concerns

  • Unescaped output detected
  • Missing nonce checks on all entry points
  • Missing capability checks on all entry points
Vulnerabilities
None known

X3P0: Authors Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

X3P0: Authors Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
1
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

80% escaped5 total outputs
Attack Surface

X3P0: Authors Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionplugins_loadedplugin.php:30
actioninitsrc\Block\BlockRegistrar.php:37
actionrest_api_initsrc\Block\BlockRegistrar.php:38
Maintenance & Trust

X3P0: Authors Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedFeb 23, 2026
PHP min version8.1
Downloads606

Community Trust

Rating0/100
Number of ratings0
Active installs40
Developer Profile

X3P0: Authors Developer Profile

Justin Tadlock

33 plugins · 34K total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect X3P0: Authors

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/x3p0-authors/public/blocks/x3p0/authors/block.json/wp-content/plugins/x3p0-authors/public/blocks/x3p0/authors/editor.js/wp-content/plugins/x3p0-authors/public/blocks/x3p0/authors/style.css/wp-content/plugins/x3p0-authors/public/blocks/x3p0/authors/view.js
Script Paths
/wp-content/plugins/x3p0-authors/public/blocks/x3p0/authors/editor.js/wp-content/plugins/x3p0-authors/public/blocks/x3p0/authors/view.js
Version Parameters
x3p0-authors/public/blocks/x3p0/authors/editor.js?ver=x3p0-authors/public/blocks/x3p0/authors/style.css?ver=x3p0-authors/public/blocks/x3p0/authors/view.js?ver=

HTML / DOM Fingerprints

CSS Classes
wp-block-x3p0-authors__linkwp-block-x3p0-authors__metawp-block-x3p0-authors__feedwp-block-x3p0-authors__countwp-block-x3p0-authors__authorwp-block-x3p0-authors__content
Data Attributes
data-wp-block="x3p0/authors"
REST Endpoints
/wp-json/wp/v2/users?x3p0_authors_post_count=
Shortcode Output
<ul class="wp-block-x3p0-authors__author"<div class="wp-block-x3p0-authors__content">
FAQ

Frequently Asked Questions about X3P0: Authors