Do Shortcode Widget EveryWhere – WPSHARE247 Security & Risk Analysis

wordpress.org/plugins/do-shortcode-widget-everywhere-wpshare247

Do Shortcode Widget EveryWhere Hiển thị Widget bất cứ đâu bạn muốn

10 active installs v1.0.1 PHP 5.6+ WP 4.9+ Updated Nov 26, 2022
do_shortcodeshortcodesidebarthe_widgetwidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Do Shortcode Widget EveryWhere – WPSHARE247 Safe to Use in 2026?

Generally Safe

Score 85/100

Do Shortcode Widget EveryWhere – WPSHARE247 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "do-shortcode-widget-everywhere-wpshare247" plugin, version 1.0.1, demonstrates a strong security posture based on the provided static analysis and vulnerability history. The absence of dangerous functions, SQL queries requiring sanitization, file operations, and external HTTP requests is commendable. Furthermore, all output is properly escaped, and the plugin does not bundle any libraries, reducing the risk of known vulnerabilities in third-party code. The fact that there are no recorded CVEs, past or present, indicates a history of secure development or a lack of targeting by attackers.

However, the analysis reveals a potential area for concern: the lack of nonce checks and capability checks across all entry points. While there is only one identified entry point (a shortcode) and it is not classified as unprotected in terms of authentication, the absence of these specific security measures means that the shortcode functionality might be susceptible to CSRF attacks if it performs any sensitive actions or modifies data without proper validation. Although no taint flows were identified, this absence of explicit checks could be a weak point if the shortcode's output or behavior is influenced by user input that isn't thoroughly sanitized or validated within the shortcode's handler.

In conclusion, the plugin is generally well-developed with good security practices. The lack of known vulnerabilities and the secure handling of data and code execution are significant strengths. The primary weakness lies in the potential absence of robust CSRF protection mechanisms (nonces) and authorization checks (capabilities) on its single shortcode entry point. While this has not led to any identified vulnerabilities to date, it represents a potential attack vector that could be addressed to further strengthen the plugin's security.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Do Shortcode Widget EveryWhere – WPSHARE247 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Do Shortcode Widget EveryWhere – WPSHARE247 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped4 total outputs
Attack Surface

Do Shortcode Widget EveryWhere – WPSHARE247 Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[wpshare247_pro_widget_html] inc\wpshare247_pro_shortcode.php:13
WordPress Hooks 5
actionin_widget_forminc\wpshare247_pro_shortcode.php:7
filterwidget_update_callbackinc\wpshare247_pro_shortcode.php:10
actionadmin_headinc\wpshare247_pro_shortcode.php:18
filterplugin_action_linksinc\wpshare247_pro_shortcode.php:22
actionplugins_loadedinc\wpshare247_pro_shortcode.php:23
Maintenance & Trust

Do Shortcode Widget EveryWhere – WPSHARE247 Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedNov 26, 2022
PHP min version5.6
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Do Shortcode Widget EveryWhere – WPSHARE247 Developer Profile

Website366.com

7 plugins · 5K total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Do Shortcode Widget EveryWhere – WPSHARE247

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
/wp-content/plugins/do-shortcode-widget-everywhere-wpshare247/inc/wpshare247_pro_shortcode.php

HTML / DOM Fingerprints

CSS Classes
wp-pro-bg
Data Attributes
onClicktitlestyle
JS Globals
wpshare247_copy_shortcode
Shortcode Output
[wpshare247_pro_widget_html widget_id=
FAQ

Frequently Asked Questions about Do Shortcode Widget EveryWhere – WPSHARE247