
Custom ShortCode Creator Security & Risk Analysis
wordpress.org/plugins/custom-shortcode-creatorThis Custom Shotcode Creator plugin allows you to quickly define custom shortcodes via admin dashboard without any hassle.
Is Custom ShortCode Creator Safe to Use in 2026?
Generally Safe
Score 85/100Custom ShortCode Creator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "custom-shortcode-creator" plugin v2.0 exhibits a mixed security posture. On the positive side, the absence of known CVEs, unpatched vulnerabilities, dangerous functions, file operations, external HTTP requests, and SQL queries that are not prepared are strong indicators of a generally well-maintained and securely coded plugin. The limited attack surface, consisting of only one shortcode and no unprotected entry points, further contributes to its security.
However, there are significant concerns regarding output escaping. The static analysis reveals that 100% of detected outputs are not properly escaped. This is a critical weakness, as unescaped output can lead to Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into web pages viewed by users. The lack of nonce checks and capability checks, while not explicitly tied to an unprotected entry point in this analysis, represents a potential risk if the shortcode's functionality interacts with user data or performs sensitive operations.
In conclusion, while the plugin benefits from a clean vulnerability history and robust practices in areas like SQL and attack surface management, the pervasive issue of unescaped output presents a substantial risk. This weakness must be addressed to mitigate potential XSS attacks and ensure the plugin's overall security.
Key Concerns
- All outputs are unescaped
- No nonce checks implemented
- No capability checks implemented
Custom ShortCode Creator Security Vulnerabilities
Custom ShortCode Creator Code Analysis
Output Escaping
Custom ShortCode Creator Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
Custom ShortCode Creator Maintenance & Trust
Maintenance Signals
Community Trust
Custom ShortCode Creator Alternatives
Post Content Shortcodes
post-content-shortcodes
Adds shortcodes to display the content of a post or a list of posts.
Post Content Shortcode
post-content-shortcode
Embed the content of another post using a simple shortcode. Useful for reusing content across pages or posts.
Wpautop Mask
wpautop-mask
Toggle wpautop with shortcodes.
In This Article
in-this-article
Fetches all H2 and H3 tags from post content and allows displaying them in a clickable list using a shortcode.
WP Shortcodes Plugin — Shortcodes Ultimate
shortcodes-ultimate
A comprehensive collection of visual components for your site
Custom ShortCode Creator Developer Profile
4 plugins · 260 total installs
How We Detect Custom ShortCode Creator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-shortcode-creator/images/image.pngHTML / DOM Fingerprints
[shortcode id="