
Awesome Shortcodes Security & Risk Analysis
wordpress.org/plugins/awesome-shortcodesAwesome shortcodes.
Is Awesome Shortcodes Safe to Use in 2026?
Generally Safe
Score 99/100Awesome Shortcodes has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The static analysis of 'awesome-shortcodes' v1.7.4 indicates a generally strong security posture with no identified dangerous functions, file operations, or external HTTP requests. The plugin also exclusively uses prepared statements for SQL queries and boasts a high percentage of properly escaped output, which are excellent security practices. However, the presence of two flows with unsanitized paths, even though not classified as critical or high severity in the taint analysis, warrants attention as it suggests potential avenues for unexpected behavior or data leakage if these paths are ever exposed to user input.
The vulnerability history shows one previously disclosed medium-severity vulnerability of the Cross-site Scripting (XSS) type, which was successfully patched. The fact that there are no currently unpatched vulnerabilities is positive, but the historical XSS vulnerability, combined with the identified unsanitized paths in the taint analysis, suggests that careful input validation and output sanitization should remain a focus. While the attack surface appears minimal and all entry points seem protected, the taint analysis findings are the most significant area for improvement to further harden the plugin.
In conclusion, 'awesome-shortcodes' v1.7.4 demonstrates good development practices by minimizing dangerous code patterns and securing its data interactions. The primary concern lies in the two unsanitized paths identified by taint analysis, which, though not currently critical, represent a potential risk that could be exacerbated by future code changes or more sophisticated attack vectors. Addressing these specific flows would significantly improve the plugin's overall security resilience.
Key Concerns
- Taint flows with unsanitized paths
- History of medium severity XSS vulnerability
Awesome Shortcodes Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Awesome Shortcodes <= 1.7.2 - Reflected Cross-Site Scripting
Awesome Shortcodes Release Timeline
Awesome Shortcodes Code Analysis
Output Escaping
Data Flow Analysis
Awesome Shortcodes Attack Surface
WordPress Hooks 9
Maintenance & Trust
Awesome Shortcodes Maintenance & Trust
Maintenance Signals
Community Trust
Awesome Shortcodes Alternatives
Ultimate Icon Shortcodes – LITE
ultimate-icon-shortcodes
This plugin will add a small button to your post / page editor, clicking on that will bring up our visual icon selector. Choose the icon you want and …
Column Shortcodes
column-shortcodes
Adds shortcodes to easily create columns in your posts or pages.
Apollo13 Framework Extensions
apollo13-framework-extensions
Adds custom post types, shortcodes and some features that are used in themes built on Apollo13 Framework.
Futurio Extra
futurio-extra
Futurio Extra add extra features to Futurio theme like widgets, WooCommerce options, Elementor widgets, one click demo import and much more.
ND Shortcodes
nd-shortcodes
The plugin adds some useful components to your page builder ( Elementor or WP Bakery Page Builder ). All components are full responsive and retina rea …
Awesome Shortcodes Developer Profile
64 plugins · 137K total installs
How We Detect Awesome Shortcodes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/awesome-shortcodes/assets/css//wp-content/plugins/awesome-shortcodes/assets/js//wp-content/plugins/awesome-shortcodes/assets/js/awesome-shortcodes/style.css?ver=alg-awesome-shortcodes-script?ver=