
Basic URL ShortCodes Security & Risk Analysis
wordpress.org/plugins/basic-url-shortcodesProvides simple shortcodes to output essential WordPress URLs inside posts, pages and widgets.
Is Basic URL ShortCodes Safe to Use in 2026?
Generally Safe
Score 100/100Basic URL ShortCodes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'basic-url-shortcodes' plugin, version 4.0.2, exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, file operations, external HTTP requests, and the exclusive use of prepared statements for SQL queries are commendable. Furthermore, all identified output appears to be properly escaped, and there are no recorded vulnerabilities in its history, suggesting a low overall risk profile and consistent security development practices.
However, there are areas that raise concern, particularly the complete lack of nonce checks and capability checks across all identified entry points. With three shortcodes present, this absence creates a potential avenue for Cross-Site Request Forgery (CSRF) attacks if these shortcodes perform any sensitive actions. While the taint analysis found no unsanitized paths, the lack of explicit authorization mechanisms on these shortcodes means that any user, even an unauthenticated one if the shortcodes are accessible publicly, could potentially trigger their functionality. The lack of any identified AJAX handlers or REST API routes does limit the immediate attack surface, but the shortcode functionality remains a point of attention.
In conclusion, 'basic-url-shortcodes' v4.0.2 is a plugin that demonstrates good practices in areas like SQL and output sanitization, and its vulnerability history is clean. The primary weakness lies in the missing authorization and CSRF protection for its shortcode entry points. While no active vulnerabilities are apparent, the potential for exploitation exists due to these missing security controls. It is recommended that the developers implement nonce and capability checks for all shortcodes.
Key Concerns
- Missing nonce checks on shortcodes
- Missing capability checks on shortcodes
Basic URL ShortCodes Security Vulnerabilities
Basic URL ShortCodes Code Analysis
Output Escaping
Basic URL ShortCodes Attack Surface
Shortcodes 3
Maintenance & Trust
Basic URL ShortCodes Maintenance & Trust
Maintenance Signals
Community Trust
Basic URL ShortCodes Alternatives
URL ShortCodes
url-shortcodes
URL ShortCodes plugin adds support for a basic short codes to use in your post/page editor that produce correct absolute URLs.
Email addon for CF7
cf7-email-add-on
Email addon for CF7 plugin provides the responsive Email templates to admin and users.
Shortcodely
shortcodely
Enable the usage of shortcodes almost any where on your website
Lotos Likes
lotos-likes
Add "like" functionality to your posts and pages
Show template by shortcode for Elementor
anywhere-elementor-template
Display Elementor sections/canvas/templates using shortcode in anywhere of your site.
Basic URL ShortCodes Developer Profile
6 plugins · 3K total installs
How We Detect Basic URL ShortCodes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
basic-url-shortcodes/style.css?ver=basic-url-shortcodes/script.js?ver=HTML / DOM Fingerprints
<a href="">