
Do Shortcode Widget EveryWhere – WPSHARE247 Security & Risk Analysis
wordpress.org/plugins/do-shortcode-widget-everywhere-wpshare247Do Shortcode Widget EveryWhere Hiển thị Widget bất cứ đâu bạn muốn
Is Do Shortcode Widget EveryWhere – WPSHARE247 Safe to Use in 2026?
Generally Safe
Score 85/100Do Shortcode Widget EveryWhere – WPSHARE247 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "do-shortcode-widget-everywhere-wpshare247" plugin, version 1.0.1, demonstrates a strong security posture based on the provided static analysis and vulnerability history. The absence of dangerous functions, SQL queries requiring sanitization, file operations, and external HTTP requests is commendable. Furthermore, all output is properly escaped, and the plugin does not bundle any libraries, reducing the risk of known vulnerabilities in third-party code. The fact that there are no recorded CVEs, past or present, indicates a history of secure development or a lack of targeting by attackers.
However, the analysis reveals a potential area for concern: the lack of nonce checks and capability checks across all entry points. While there is only one identified entry point (a shortcode) and it is not classified as unprotected in terms of authentication, the absence of these specific security measures means that the shortcode functionality might be susceptible to CSRF attacks if it performs any sensitive actions or modifies data without proper validation. Although no taint flows were identified, this absence of explicit checks could be a weak point if the shortcode's output or behavior is influenced by user input that isn't thoroughly sanitized or validated within the shortcode's handler.
In conclusion, the plugin is generally well-developed with good security practices. The lack of known vulnerabilities and the secure handling of data and code execution are significant strengths. The primary weakness lies in the potential absence of robust CSRF protection mechanisms (nonces) and authorization checks (capabilities) on its single shortcode entry point. While this has not led to any identified vulnerabilities to date, it represents a potential attack vector that could be addressed to further strengthen the plugin's security.
Key Concerns
- Missing nonce checks
- Missing capability checks
Do Shortcode Widget EveryWhere – WPSHARE247 Security Vulnerabilities
Do Shortcode Widget EveryWhere – WPSHARE247 Code Analysis
Output Escaping
Do Shortcode Widget EveryWhere – WPSHARE247 Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
Do Shortcode Widget EveryWhere – WPSHARE247 Maintenance & Trust
Maintenance Signals
Community Trust
Do Shortcode Widget EveryWhere – WPSHARE247 Alternatives
Disable Author Pages
disable-author-pages
Disable the author pages
Nested Shortcodes by Outerbridge
nested-shortcodes
A small plugin which allows you to use nest shortcodes (i.e. a shortcode within an enclosing shortcode) by implementing a simple do_shortcode filter
Sidebar Shortcode
thinker-sidebar-shortcode
Add sidebars to WordPress posts and pages using shortcodes with a sidebar Name or ID.
CC BMI Calculator
cc-bmi-calculator
Add a free simple customizable BMI Calculator to your web site.
WordPress Widgets Shortcode
wp-widgets-shortcode
Embed any widget area/dynamic sidebar to your pages/posts using the shortcode [dynamic-sidebar id='Your Widget Area/Sidebar name']
Do Shortcode Widget EveryWhere – WPSHARE247 Developer Profile
7 plugins · 5K total installs
How We Detect Do Shortcode Widget EveryWhere – WPSHARE247
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/do-shortcode-widget-everywhere-wpshare247/inc/wpshare247_pro_shortcode.phpHTML / DOM Fingerprints
wp-pro-bgonClicktitlestylewpshare247_copy_shortcode[wpshare247_pro_widget_html widget_id=