
Arconix Shortcodes Security & Risk Analysis
wordpress.org/plugins/arconix-shortcodesArconix Shortcodes provides a number of useful design elements like buttons, boxes, tabs and toggles to help compliment any website.
Is Arconix Shortcodes Safe to Use in 2026?
Mostly Safe
Score 72/100Arconix Shortcodes is generally safe to use. 10 past CVEs were resolved.
The Arconix Shortcodes plugin version 2.1.19 presents a mixed security posture. On the positive side, static analysis indicates a small attack surface with no identified shortcodes, cron events, or REST API routes, and the single AJAX handler appears to have authentication checks. SQL queries are exclusively using prepared statements, and there are no file operations or bundled libraries to worry about. Taint analysis also reveals no critical or high severity flows with unsanitized paths.
However, significant concerns arise from the plugin's vulnerability history. A substantial number of past CVEs (10 in total) indicate a recurring pattern of security weaknesses. The presence of one currently unpatched vulnerability, specifically a medium severity Cross-site Scripting (XSS) or Missing Authorization issue, is a critical red flag. Furthermore, the output escaping is only properly implemented in 60% of cases, leaving a considerable portion of output potentially vulnerable to XSS attacks. The 2 external HTTP requests also warrant scrutiny, as their implementation and handling of external data could introduce vulnerabilities.
In conclusion, while the plugin demonstrates some good security practices in its current code structure, the extensive history of vulnerabilities and the unpatched CVE strongly suggest a need for caution. The unescaped output further contributes to the risk profile. Users should prioritize addressing the unpatched vulnerability and consider the potential risks associated with the remaining unescaped output.
Key Concerns
- Unpatched CVE
- Medium severity vulnerability history (10)
- Output escaping only 60% properly
- External HTTP requests
Arconix Shortcodes Security Vulnerabilities
CVEs by Year
Severity Breakdown
10 total CVEs
Arconix Shortcodes <= 2.1.19 - Authenticated (Contributor+) Stored Cross-Site Scripting
Arconix Shortcodes <= 2.1.18 - Missing Authorization
Arconix Shortcodes <= 2.1.17 - Authenticated (Contributor+) Stored Cross-Site Scripting
Arconix Shortcodes <= 2.1.16 - Reflected Cross-Site Scripting
Arconix Shortcodes <= 2.1.15 - Reflected Cross-Site Scripting
Arconix Shortcodes <= 2.1.14 - Authenticated (Contributor+) Stored Cross-Site Scripting
Arconix Shortcodes <= 2.1.13 - Authenticated (Contributor+) Stored Cross-Site Scripting via box Shortcode
Arconix Shortcodes <= 2.1.12 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Arconix Shortcodes <= 2.1.11 - Missing Authorization
Arconix Shortcodes <= 2.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode
Arconix Shortcodes Release Timeline
Arconix Shortcodes Code Analysis
Output Escaping
Data Flow Analysis
Arconix Shortcodes Attack Surface
AJAX Handlers 1
WordPress Hooks 22
Maintenance & Trust
Arconix Shortcodes Maintenance & Trust
Maintenance Signals
Community Trust
Arconix Shortcodes Alternatives
Meks Flexible Shortcodes
meks-flexible-shortcodes
Add some cool elements to your post/page content with flexible shortcodes.
WP Shortcode by MyThemeShop
wp-shortcode
WP Shortcode is a premium WP plugin for free, that provides easy to use over 24 shortcodes. You can easily add buttons, alerts, videos and more.
Rescue Shortcodes
rescue-shortcodes
A lightweight WordPress shortcodes plugin.
Shortcode Revolution
shortcode-revolution
Shortcode everything. The low code / no code tool for WordPress developers, designers, and power users. /*** This program is free software: you can …
PixCodes
pixcodes
PixCodes offers you a nice interface to add shortcodes into editor.
Arconix Shortcodes Developer Profile
20 plugins · 159K total installs
How We Detect Arconix Shortcodes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/arconix-shortcodes/includes/jquery.tools.min.js/wp-content/plugins/arconix-shortcodes/includes/css/font-awesome.min.css/wp-content/plugins/arconix-shortcodes/includes/arconix-shortcodes.js/wp-content/plugins/arconix-shortcodes/includes/arconix-shortcodes.min.js/wp-content/plugins/arconix-shortcodes/includes/css/arconix-shortcodes.css/wp-content/plugins/arconix-shortcodes/includes/css/arconix-shortcodes.min.css/wp-content/plugins/arconix-shortcodes/includes/jquery.tools.min.js/wp-content/plugins/arconix-shortcodes/includes/arconix-shortcodes.js/wp-content/plugins/arconix-shortcodes/includes/arconix-shortcodes.min.jsarconix-shortcodes/includes/jquery.tools.min.js?ver=arconix-shortcodes/includes/css/font-awesome.min.css?ver=arconix-shortcodes/includes/arconix-shortcodes.js?ver=arconix-shortcodes/includes/arconix-shortcodes.min.js?ver=arconix-shortcodes/includes/css/arconix-shortcodes.css?ver=arconix-shortcodes/includes/css/arconix-shortcodes.min.css?ver=HTML / DOM Fingerprints
arconix-accordionsac-accordionsac-tabac-tabsac-tabs-navac-tabs-contentarconix-buttonac-button+27 more<!-- End Arconix Shortcodes --><!-- Initialize Arconix Shortcodes --><!-- END Arconix Tabs -->data-plugin-namedata-plugin-versiondata-plugin-authordata-plugin-uridata-ac-sliderdata-ac-tooltip+1 morearconix_shortcodes<div class="arconix-accordions"><div class="ac-accordions"><div class="ac-tab"><div class="ac-tabs">