
DCO Shortcodes Menu Security & Risk Analysis
wordpress.org/plugins/dco-shortcodes-menuAllow you to add shortcodes menu to the editor
Is DCO Shortcodes Menu Safe to Use in 2026?
Generally Safe
Score 85/100DCO Shortcodes Menu has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "dco-shortcodes-menu" plugin v1.0.1 exhibits a strong security posture based on the provided static analysis. There are no identified vulnerabilities in its history, and the static analysis reveals a remarkably clean codebase with zero identified attack surface entry points. The absence of dangerous functions, file operations, and external HTTP requests further bolsters its security. Crucially, the plugin demonstrates good practices by utilizing prepared statements for all SQL queries, implementing nonce checks, and performing capability checks on relevant code paths. The 53% proper output escaping, while not perfect, is acceptable given the absence of critical taint flows or other serious security concerns in the static analysis. The plugin's zero-vulnerability history strongly suggests consistent security focus and good development practices over time.
While the plugin scores highly on security, the 47% of output that is not properly escaped represents a minor area of concern. Although no critical taint flows were identified, in a more complex plugin, this could lead to Cross-Site Scripting (XSS) vulnerabilities if untrusted data were to reach these unescaped output points. However, given the very limited attack surface and the plugin's overall clean bill of health, this is a low-severity concern. The plugin's strengths lie in its proactive avoidance of common vulnerabilities and its robust use of WordPress security features. The primary weakness, though minor in this context, is the incomplete output escaping.
Key Concerns
- Unescaped output
DCO Shortcodes Menu Security Vulnerabilities
DCO Shortcodes Menu Code Analysis
Output Escaping
DCO Shortcodes Menu Attack Surface
WordPress Hooks 20
Maintenance & Trust
DCO Shortcodes Menu Maintenance & Trust
Maintenance Signals
Community Trust
DCO Shortcodes Menu Alternatives
Crazy Pills
crazy-pills
Build buttons, boxes, beautiful lists, and highlight text right from your editor, with live preview.
Easy Tinymce Editor Add Button
easy-tinymce-editor-add-button
Simple plugin for adding buttons to the html wp panel of the tinymce editor. Features: Ease of use Ability to add any content Unlimited number of b …
TinyMCE Generic WP Shortcode Editor
tinymce-generic-wp-shortcode-editor
It makes TinyMCE able to create or edit shortcodes in a visual way.
Priority Shortcodes
priority-shortcodes
Processes specific shortcodes before wpautop() and do_shortcode()
Kabook Editor Tools
kabook-editor-tools
Supercharge WordPress: Modular UI Elements, Image Effects, Sticky Media Player & a unified Toolkit for Classic & Gutenberg.
DCO Shortcodes Menu Developer Profile
5 plugins · 13K total installs
How We Detect DCO Shortcodes Menu
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dco-shortcodes-menu/dco-sm-metaboxes.js/wp-content/plugins/dco-shortcodes-menu/dco-sm-metaboxes.css/wp-content/plugins/dco-shortcodes-menu/dco-sm-metaboxes.jsdco-shortcodes-menu/dco-sm-metaboxes.css?ver=dco-shortcodes-menu/dco-sm-metaboxes.js?ver=HTML / DOM Fingerprints
dco-sm-fields-listdco-sm-field-typesdco-sm-field-typedata-typedata-editdata-adddata-default