BibleGateway Links Shortcode Security & Risk Analysis

wordpress.org/plugins/biblegateway-links-shortcode

Shortcode for linking Bible references to a BibleGateway page.

90 active installs v0.1.7 PHP + WP 3.2+ Updated Jan 16, 2015
biblebiblegatewaybuttoneditorshortcode
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is BibleGateway Links Shortcode Safe to Use in 2026?

Generally Safe

Score 85/100

BibleGateway Links Shortcode has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The biblegateway-links-shortcode plugin, version 0.1.7, exhibits a generally positive security posture with no known vulnerabilities or critical code signals. The absence of dangerous functions, external HTTP requests, and the consistent use of prepared statements for all SQL queries are strong indicators of good security practices. Furthermore, the plugin demonstrates a controlled attack surface, with only one shortcode identified and no AJAX handlers or REST API routes that lack authorization checks.

However, a notable concern lies in the output escaping. With 57% of outputs properly escaped, there is a significant risk that the remaining 43% could be vulnerable to cross-site scripting (XSS) attacks. The lack of nonces and capability checks, while not directly flagged as a risk given the current attack surface, could become a concern if the plugin were to evolve and introduce more complex functionalities or if its attack surface were to expand without proper security controls.

The plugin's clean vulnerability history, with zero recorded CVEs, is a significant strength. This suggests a history of responsible development and a low likelihood of undiscovered critical flaws. In conclusion, while the plugin demonstrates good foundational security, the unescaped output presents a tangible risk that should be addressed to achieve a more robust security profile.

Key Concerns

  • Output escaping is not fully implemented
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

BibleGateway Links Shortcode Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

BibleGateway Links Shortcode Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

57% escaped7 total outputs
Attack Surface

BibleGateway Links Shortcode Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[biblegateway] biblegateway-search-shortcode.php:62
WordPress Hooks 7
actionadmin_initbiblegateway-search-shortcode.php:58
actionadmin_menubiblegateway-search-shortcode.php:59
actionadmin_footerbiblegateway-search-shortcode.php:60
actionadmin_enqueue_scriptsbiblegateway-search-shortcode.php:61
filtermce_external_pluginsbiblegateway-search-shortcode.php:66
filtermce_buttonsbiblegateway-search-shortcode.php:67
actionwp_footerbiblegateway-search-shortcode.php:201
Maintenance & Trust

BibleGateway Links Shortcode Maintenance & Trust

Maintenance Signals

WordPress version tested4.2.0
Last updatedJan 16, 2015
PHP min version
Downloads5K

Community Trust

Rating100/100
Number of ratings1
Active installs90
Developer Profile

BibleGateway Links Shortcode Developer Profile

Justin Sternberg

8 plugins · 301K total installs

90
trust score
Avg Security Score
85/100
Avg Patch Time
7 days
View full developer profile
Detection Fingerprints

How We Detect BibleGateway Links Shortcode

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/biblegateway-links-shortcode/register-bg.js/wp-content/plugins/biblegateway-links-shortcode/register-bg-html.js
Script Paths
/wp-content/plugins/biblegateway-links-shortcode/register-bg.js/wp-content/plugins/biblegateway-links-shortcode/register-bg-html.js
Version Parameters
biblegateway-links-shortcode/register-bg.js?ver=biblegateway-links-shortcode/register-bg-html.js?ver=

HTML / DOM Fingerprints

CSS Classes
biblerefbible-gateway
HTML Comments
http://bibles.org/pages/highlighterhttps://wordpress.org/plugins/biblegateway-links-shortcode/https://wordpress.org/plugins/biblegateway-links-shortcode/
Data Attributes
data-version
JS Globals
biblegwlinkpop_bhparsebw-highlighter-src
Shortcode Output
<cite class="bibleref"<a class="bible-gateway" href="
FAQ

Frequently Asked Questions about BibleGateway Links Shortcode