DCO Shortcodes Menu Security & Risk Analysis

wordpress.org/plugins/dco-shortcodes-menu

Allow you to add shortcodes menu to the editor

10 active installs v1.0.1 PHP + WP 4.6+ Updated Jan 19, 2018
editorinsert-shortcodeshortcodeshortcodes-menutinymce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is DCO Shortcodes Menu Safe to Use in 2026?

Generally Safe

Score 85/100

DCO Shortcodes Menu has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The "dco-shortcodes-menu" plugin v1.0.1 exhibits a strong security posture based on the provided static analysis. There are no identified vulnerabilities in its history, and the static analysis reveals a remarkably clean codebase with zero identified attack surface entry points. The absence of dangerous functions, file operations, and external HTTP requests further bolsters its security. Crucially, the plugin demonstrates good practices by utilizing prepared statements for all SQL queries, implementing nonce checks, and performing capability checks on relevant code paths. The 53% proper output escaping, while not perfect, is acceptable given the absence of critical taint flows or other serious security concerns in the static analysis. The plugin's zero-vulnerability history strongly suggests consistent security focus and good development practices over time.

While the plugin scores highly on security, the 47% of output that is not properly escaped represents a minor area of concern. Although no critical taint flows were identified, in a more complex plugin, this could lead to Cross-Site Scripting (XSS) vulnerabilities if untrusted data were to reach these unescaped output points. However, given the very limited attack surface and the plugin's overall clean bill of health, this is a low-severity concern. The plugin's strengths lie in its proactive avoidance of common vulnerabilities and its robust use of WordPress security features. The primary weakness, though minor in this context, is the incomplete output escaping.

Key Concerns

  • Unescaped output
Vulnerabilities
None known

DCO Shortcodes Menu Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

DCO Shortcodes Menu Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
25
28 escaped
Nonce Checks
1
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

53% escaped53 total outputs
Attack Surface

DCO Shortcodes Menu Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 20
actioninitdco-sm-metaboxes.php:9
actionadmin_enqueue_scriptsdco-sm-metaboxes.php:13
filterenter_title_heredco-sm-metaboxes.php:14
actionadmin_menudco-sm-metaboxes.php:15
actionadd_meta_boxesdco-sm-metaboxes.php:16
actionsave_postdco-sm-metaboxes.php:17
actionadmin_initdco-sm-posttype.php:9
actioninitdco-sm-posttype.php:10
actionpost_row_actionsdco-sm-posttype.php:14
filtermanage_dco_shortcode_posts_columnsdco-sm-posttype.php:15
actionmanage_dco_shortcode_posts_custom_columndco-sm-posttype.php:16
actionadmin_menudco-sm-posttype.php:17
filterview_mode_post_typesdco-sm-posttype.php:18
filtermonths_dropdown_resultsdco-sm-posttype.php:19
actionrestrict_manage_postsdco-sm-posttype.php:20
actionpre_get_postsdco-sm-posttype.php:21
actioninitdco-sm.php:9
actionadmin_footerdco-sm.php:15
filtermce_external_pluginsdco-sm.php:16
filtermce_buttonsdco-sm.php:17
Maintenance & Trust

DCO Shortcodes Menu Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedJan 19, 2018
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

DCO Shortcodes Menu Developer Profile

Denis Yanchevskiy

5 plugins · 13K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect DCO Shortcodes Menu

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/dco-shortcodes-menu/dco-sm-metaboxes.js/wp-content/plugins/dco-shortcodes-menu/dco-sm-metaboxes.css
Script Paths
/wp-content/plugins/dco-shortcodes-menu/dco-sm-metaboxes.js
Version Parameters
dco-shortcodes-menu/dco-sm-metaboxes.css?ver=dco-shortcodes-menu/dco-sm-metaboxes.js?ver=

HTML / DOM Fingerprints

CSS Classes
dco-sm-fields-listdco-sm-field-typesdco-sm-field-type
Data Attributes
data-typedata-editdata-adddata-default
FAQ

Frequently Asked Questions about DCO Shortcodes Menu