
CTA Shortcodes for Post Security & Risk Analysis
wordpress.org/plugins/cta-shortcodes-in-post"CTA Shortcodes in Post" is a free plugin that allows you to embed "Call to Action" in articles and pages using a simple "Sho …
Is CTA Shortcodes for Post Safe to Use in 2026?
Generally Safe
Score 85/100CTA Shortcodes for Post has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the provided static analysis and vulnerability history, the "cta-shortcodes-in-post" plugin version 1.0.0 exhibits a generally strong security posture. The code analysis reveals excellent practices, with all SQL queries utilizing prepared statements and all output being properly escaped. The absence of dangerous functions, file operations, external HTTP requests, and a limited attack surface (only one shortcode with no observed unprotected entry points) further contribute to its security. The lack of any recorded vulnerabilities, past or present, also suggests a history of secure development and maintenance.
However, there are a few areas that, while not currently flagged as vulnerabilities, represent potential security concerns. The plugin does not implement nonce checks or capability checks, which are fundamental security mechanisms in WordPress for preventing Cross-Site Request Forgery (CSRF) and ensuring proper authorization for actions initiated through the shortcode. While the current entry point (the shortcode) might not immediately expose a critical vulnerability due to the lack of exploitable functions and proper output escaping, future updates or modifications could inadvertently introduce risks if these checks are not implemented. Therefore, the plugin has strengths in its current implementation and history but lacks some standard WordPress security controls that should be addressed for robust protection.
The absence of taint analysis results and the limited scope of the static analysis are notable. While no issues were found, it's possible that more complex or indirect attack vectors were not detected with the current analysis depth. The overall picture is of a plugin that is currently safe but could benefit from enhanced authorization and CSRF protection mechanisms to align with best practices and mitigate future risks.
Key Concerns
- Missing nonce checks
- Missing capability checks
CTA Shortcodes for Post Security Vulnerabilities
CTA Shortcodes for Post Code Analysis
Output Escaping
CTA Shortcodes for Post Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
CTA Shortcodes for Post Maintenance & Trust
Maintenance Signals
Community Trust
CTA Shortcodes for Post Alternatives
WEN Call To Action
wen-call-to-action
Easily create call to action for your WordPress site
Mobile Contact Bar
mobile-contact-bar
Allow your visitors to contact you via mobile phones, or access your site's pages instantly.
Call to Action Block by WPPOOL
call-to-action-block-wppool
Add a stunning call to action (CTA) block to your WordPress post or page using 10+ prebuilt call to action layouts for Gutenberg.
CTA Button Styler
cta-button-styler
Increase engagement with reusable CTA buttons, styled your way with hover effects and optional animations. Clean and efficient.
Easy Call To Action
easy-call-to-action
Create Call To Actions and generate shortcodes to insert them in post, pages or widgets.
CTA Shortcodes for Post Developer Profile
1 plugin · 0 total installs
How We Detect CTA Shortcodes for Post
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cta-shortcodes-in-post/css/cta-shortcodes.css/wp-content/plugins/cta-shortcodes-in-post/js/alpha-color-picker.js/wp-content/plugins/cta-shortcodes-in-post/css/alpha-color-picker.css/wp-content/plugins/cta-shortcodes-in-post/js/alpha-color-picker.jsHTML / DOM Fingerprints
alpha-color-pickerdata-alpha-enableddata-default-colorjQuery<div class="cta_shortcodes_container"<h2 class="cta_shortcodes_title"<div class="cta_shortcodes_text_button"<div class="cta_shortcodes_link_button"