
Clean unused shortcodes Security & Risk Analysis
wordpress.org/plugins/clean-unused-shortcodesRemove unused shortcodes from your posts content with an improved user interface and advanced functionality.
Is Clean unused shortcodes Safe to Use in 2026?
Generally Safe
Score 100/100Clean unused shortcodes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "clean-unused-shortcodes" plugin v2.0.1 presents a mixed security posture. On the positive side, the plugin demonstrates good practices by exclusively using prepared statements for SQL queries, ensuring all detected output is properly escaped, and having no file operations or external HTTP requests. The absence of known vulnerabilities in its history is also a strong indicator of historical security diligence.
However, a significant concern is the plugin's substantial attack surface, consisting of six AJAX handlers, all of which lack authentication checks. This means any unauthenticated user could potentially trigger these handlers, leading to unintended actions or information disclosure if vulnerabilities exist within them. While taint analysis found no critical or high-severity issues, the lack of capability checks on these AJAX handlers is a notable weakness, as it bypasses WordPress's user role and permission system.
In conclusion, while the plugin's internal code quality regarding SQL and output handling is commendable, the exposed AJAX endpoints without proper authentication represent a significant security risk that should be addressed. The lack of past vulnerabilities is encouraging, but the current design flaw in its attack surface management requires immediate attention to mitigate potential exploitation.
Key Concerns
- AJAX handlers without auth checks
- No capability checks on AJAX
Clean unused shortcodes Security Vulnerabilities
Clean unused shortcodes Code Analysis
Bundled Libraries
Output Escaping
Clean unused shortcodes Attack Surface
AJAX Handlers 6
WordPress Hooks 4
Maintenance & Trust
Clean unused shortcodes Maintenance & Trust
Maintenance Signals
Community Trust
Clean unused shortcodes Alternatives
WP Admin Buttons
wp-admin-buttons
Displays WordPress admin style buttons in the front end.
Content Space Analyzer
content-space-analyzer
Analyze your WordPress installation in batches, discover the heaviest files/folders, and remove selected files from wp-content.
Reset Custom Post
reset-custom-post
Reset Custom Post is a WordPress plugin that provides an easy solution for managing unwanted custom post content.
Tidy Admin Notices
tidy-admin-notices
Moves standard WordPress admin notices into a modern, React-powered Notification Center tray.
AJAX Thumbnail Rebuild
ajax-thumbnail-rebuild
AJAX Thumbnail Rebuild allows you to rebuild all thumbnails at once without script timeouts on your server.
Clean unused shortcodes Developer Profile
2 plugins · 100 total installs
How We Detect Clean unused shortcodes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/clean-unused-shortcodes/assets/dist/admin-styles.min.css/wp-content/plugins/clean-unused-shortcodes/assets/dist/admin-scripts.min.js/wp-content/plugins/clean-unused-shortcodes/assets/dist/admin-scripts.min.jsclean-unused-shortcodes/assets/dist/admin-styles.min.css?ver=clean-unused-shortcodes/assets/dist/admin-scripts.min.js?ver=HTML / DOM Fingerprints
cus_ajax_object