
X3P0: Authors Security & Risk Analysis
wordpress.org/plugins/x3p0-authorsA customizable authors list block that lets you showcase post authors, their feed links, and post counts.
Is X3P0: Authors Safe to Use in 2026?
Generally Safe
Score 100/100X3P0: Authors has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "x3p0-authors" plugin version 2.0.0 demonstrates a strong security posture based on the provided static analysis results. There are no identified critical or high severity code signals such as dangerous functions, unsanitized taint flows, or direct SQL queries. The plugin also avoids common vulnerabilities like external HTTP requests, file operations, and the use of bundled libraries, which often serve as vectors for outdated components. Furthermore, the absence of recorded vulnerabilities in its history suggests a track record of secure development and maintenance.
However, the analysis does highlight some areas for potential concern. The complete lack of nonce checks and capability checks across all entry points, coupled with a notable percentage of output that is not properly escaped, represent weaknesses. While the attack surface appears small and currently without identified unprotected entry points, future additions or changes to the plugin could inadvertently introduce risks if these fundamental security practices are not implemented. The fact that 20% of outputs are not properly escaped could lead to Cross-Site Scripting (XSS) vulnerabilities if the unescaped data is user-supplied or sensitive.
Overall, the plugin is in a good security state due to its clean code signals and lack of historical vulnerabilities. However, the oversight in implementing nonces, capability checks, and robust output escaping on all instances is a notable deficiency that could be exploited. The plugin authors should prioritize addressing these shortcomings to further enhance its security.
Key Concerns
- Unescaped output detected
- Missing nonce checks on all entry points
- Missing capability checks on all entry points
X3P0: Authors Security Vulnerabilities
X3P0: Authors Code Analysis
SQL Query Safety
Output Escaping
X3P0: Authors Attack Surface
WordPress Hooks 3
Maintenance & Trust
X3P0: Authors Maintenance & Trust
Maintenance Signals
Community Trust
X3P0: Authors Alternatives
Latest Posts Block – Dynamic Posts Grid, Posts List, Posts Tile with Stunning Layouts for WordPress Blogs & Pages
latest-posts-block-lite
Dynamic Posts Grid, Posts List, Posts Tile with Stunning Layouts for WordPress Blogs & Pages
Events Block For The Events Calendar
events-block-for-the-events-calendar
The Events Block for The Events Calendar lets you showcase your events from The Events Calendar right within the Gutenberg pages.
Post Blocks & Tools
bnm-blocks
Post grid, post list, and post slider Gutenberg blocks to design blog and magazine layouts easily.
PostExtra – News and Magazine Blog Post Blocks for Gutenberg & FSE
post-extra
Magazine‑style post grids, lists, and carousels for Gutenberg and FSE – design high‑engagement blog and news layouts without coding.
Blocks for WP Job Manager
bhoot-blocks-wp-job-manager
Blocks for WP Job Manager are the easiest, most flexible way to display your job listings on posts and pages!
X3P0: Authors Developer Profile
33 plugins · 34K total installs
How We Detect X3P0: Authors
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/x3p0-authors/public/blocks/x3p0/authors/block.json/wp-content/plugins/x3p0-authors/public/blocks/x3p0/authors/editor.js/wp-content/plugins/x3p0-authors/public/blocks/x3p0/authors/style.css/wp-content/plugins/x3p0-authors/public/blocks/x3p0/authors/view.js/wp-content/plugins/x3p0-authors/public/blocks/x3p0/authors/editor.js/wp-content/plugins/x3p0-authors/public/blocks/x3p0/authors/view.jsx3p0-authors/public/blocks/x3p0/authors/editor.js?ver=x3p0-authors/public/blocks/x3p0/authors/style.css?ver=x3p0-authors/public/blocks/x3p0/authors/view.js?ver=HTML / DOM Fingerprints
wp-block-x3p0-authors__linkwp-block-x3p0-authors__metawp-block-x3p0-authors__feedwp-block-x3p0-authors__countwp-block-x3p0-authors__authorwp-block-x3p0-authors__contentdata-wp-block="x3p0/authors"/wp-json/wp/v2/users?x3p0_authors_post_count=<ul class="wp-block-x3p0-authors__author"<div class="wp-block-x3p0-authors__content">