
CooThemes Shortcodes Security & Risk Analysis
wordpress.org/plugins/cothemes-shortcodeCooThemes Shortcodes is a free WordPress plugin that provides a pack of shortcodes. With this powerful yet easy-to-use shortcode plugin, you can easil …
Is CooThemes Shortcodes Safe to Use in 2026?
Generally Safe
Score 85/100CooThemes Shortcodes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "cothemes-shortcode" plugin, version 1.0.4, presents a significant security risk primarily due to its extensive unprotected AJAX handlers. While the plugin demonstrates good practices in avoiding dangerous functions and utilizing prepared statements for SQL queries, the sheer number of exposed AJAX entry points without authentication or capability checks creates a large attack surface. This means any unauthenticated user could potentially trigger these handlers, leading to unintended actions or information disclosure depending on their implementation.
The taint analysis revealed a concerning number of flows with unsanitized paths, indicating a potential for path traversal vulnerabilities, although the static analysis did not flag any critical or high severity issues in this area. The lack of nonces on AJAX handlers exacerbates the risk, as it opens the door to cross-site request forgery (CSRF) attacks where attackers could trick users into executing unintended actions within the plugin.
Furthermore, the plugin's vulnerability history is empty, which is positive, but this could also be due to limited past scrutiny or analysis. In conclusion, while the plugin avoids common pitfalls like raw SQL and dangerous functions, its core design with numerous unprotected AJAX endpoints and a lack of nonce checks makes it a prime target for attackers. Addressing the unprotected AJAX handlers and implementing proper authorization and nonce checks should be the highest priority.
Key Concerns
- Unprotected AJAX handlers
- Missing nonce checks on AJAX
- Flows with unsanitized paths
- Low percentage of proper output escaping
CooThemes Shortcodes Security Vulnerabilities
CooThemes Shortcodes Code Analysis
Output Escaping
Data Flow Analysis
CooThemes Shortcodes Attack Surface
AJAX Handlers 18
WordPress Hooks 7
Maintenance & Trust
CooThemes Shortcodes Maintenance & Trust
Maintenance Signals
Community Trust
CooThemes Shortcodes Alternatives
WP Shortcode by MyThemeShop
wp-shortcode
WP Shortcode is a premium WP plugin for free, that provides easy to use over 24 shortcodes. You can easily add buttons, alerts, videos and more.
Arconix Shortcodes
arconix-shortcodes
Arconix Shortcodes provides a number of useful design elements like buttons, boxes, tabs and toggles to help compliment any website.
TinyMCE shortcode Addon
360crest-themeone-tinymce-shortcodes
Foreigncodes Tinymce Shortcodes, is a wordpress tinymce addon, that jazz up your wordpress post with cool design.
WP Shortcodes Plugin — Shortcodes Ultimate
shortcodes-ultimate
A comprehensive collection of visual components for your site
Contact Form by BestWebSoft – Advanced WP Contact Form Builder for WordPress
contact-form-plugin
The most powerful and user-friendly WordPress contact form plugin. Create beautiful contact forms, widgets and pages using shortcodes.
CooThemes Shortcodes Developer Profile
3 plugins · 60 total installs
How We Detect CooThemes Shortcodes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cothemes-shortcode/inc/css/html5tooltips.css/wp-content/plugins/cothemes-shortcode/inc/css/font-awesome.min.css/wp-content/plugins/cothemes-shortcode/inc/css/shortcode.css/wp-content/plugins/cothemes-shortcode/js/html5tooltips.js/wp-content/plugins/cothemes-shortcode/inc/js/admin.js/wp-content/plugins/cothemes-shortcode/inc/css/bootstrap.min.css/wp-content/plugins/cothemes-shortcode/inc/js/bootstrap.min.js/wp-content/plugins/cothemes-shortcode/inc/js/front.js/wp-content/plugins/cothemes-shortcode/inc/js/admin.js/wp-content/plugins/cothemes-shortcode/inc/js/front.jscothemes-shortcode/inc/css/shortcode.css?ver=cothemes-shortcode/inc/js/admin.js?ver=cothemes-shortcode/inc/css/front.css?ver=HTML / DOM Fingerprints
ctsc_shortcodesctsc_menu_icondata-idctsc_generator<a class='ctsc_shortcodes button' title='Coothemes Shortcodes'><img class='ctsc_menu_icon' src=''></a>