
Clean unused shortcodes Security & Risk Analysis
wordpress.org/plugins/clean-unused-shortcodesRemove unused shortcodes from your posts content with an improved user interface and advanced functionality.
Is Clean unused shortcodes Safe to Use in 2026?
Generally Safe
Score 100/100Clean unused shortcodes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "clean-unused-shortcodes" plugin v2.0.1 presents a mixed security posture. On the positive side, the plugin demonstrates good practices by exclusively using prepared statements for SQL queries, ensuring all detected output is properly escaped, and having no file operations or external HTTP requests. The absence of known vulnerabilities in its history is also a strong indicator of historical security diligence.
However, a significant concern is the plugin's substantial attack surface, consisting of six AJAX handlers, all of which lack authentication checks. This means any unauthenticated user could potentially trigger these handlers, leading to unintended actions or information disclosure if vulnerabilities exist within them. While taint analysis found no critical or high-severity issues, the lack of capability checks on these AJAX handlers is a notable weakness, as it bypasses WordPress's user role and permission system.
In conclusion, while the plugin's internal code quality regarding SQL and output handling is commendable, the exposed AJAX endpoints without proper authentication represent a significant security risk that should be addressed. The lack of past vulnerabilities is encouraging, but the current design flaw in its attack surface management requires immediate attention to mitigate potential exploitation.
Key Concerns
- AJAX handlers without auth checks
- No capability checks on AJAX
Clean unused shortcodes Security Vulnerabilities
Clean unused shortcodes Release Timeline
Clean unused shortcodes Code Analysis
Bundled Libraries
Output Escaping
Clean unused shortcodes Attack Surface
AJAX Handlers 6
WordPress Hooks 4
Maintenance & Trust
Clean unused shortcodes Maintenance & Trust
Maintenance Signals
Community Trust
Clean unused shortcodes Alternatives
SAC Database Inspector
sac-database-inspector
Inspect database usage, autoloaded options, transients, and safely clean database clutter from a single admin dashboard.
WP Admin Buttons
wp-admin-buttons
Displays WordPress admin style buttons in the front end.
Content Space Analyzer
content-space-analyzer
Analyze your WordPress installation in batches, discover the heaviest files/folders, and remove selected files from wp-content.
Quick Edit Post by ID (Admin Bar)
edit-by-id
Instantly open the edit screen for any post, page, or custom post type by ID, right from the WordPress admin bar.
Reset Custom Post
reset-custom-post
Reset Custom Post is a WordPress plugin that provides an easy solution for managing unwanted custom post content.
Clean unused shortcodes Developer Profile
2 plugins · 200 total installs
How We Detect Clean unused shortcodes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/clean-unused-shortcodes/assets/dist/admin-styles.min.css/wp-content/plugins/clean-unused-shortcodes/assets/dist/admin-scripts.min.js/wp-content/plugins/clean-unused-shortcodes/assets/dist/admin-scripts.min.jsclean-unused-shortcodes/assets/dist/admin-styles.min.css?ver=clean-unused-shortcodes/assets/dist/admin-scripts.min.js?ver=HTML / DOM Fingerprints
cus_ajax_object