
DobsonDev Shortcodes Security & Risk Analysis
wordpress.org/plugins/dobsondev-shortcodesAdd a collection of helpful shortcodes to your site.
Is DobsonDev Shortcodes Safe to Use in 2026?
Use With Caution
Score 64/100DobsonDev Shortcodes has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The `dobsondev-shortcodes` plugin, in version 2.1.12, exhibits a mixed security posture. On the positive side, the static analysis reveals adherence to secure coding practices, with 100% of SQL queries using prepared statements and all output being properly escaped. There are no identified dangerous functions or file operations, and the absence of unsanitized paths in taint analysis is also encouraging.
However, significant concerns arise from the plugin's vulnerability history and certain code signals. The presence of a known, unpatched medium severity CVE, specifically related to Cross-Site Scripting, is a critical issue that requires immediate attention. While the attack surface is entirely protected by authentication or capability checks, the fact that no nonce checks are implemented on AJAX handlers (though there are none) and only two capability checks are present across 23 shortcodes could indicate a potential for privilege escalation or unauthorized actions if vulnerabilities are introduced in the future. The external HTTP requests, while not inherently risky without further context, also represent potential points of exploitation if not handled securely.
In conclusion, while the current codebase appears to follow good practices for SQL and output sanitization, the single unpatched medium severity CVE for XSS is a significant weakness. This historical vulnerability suggests that the plugin may have had issues with input sanitization in the past, and the lack of explicit nonce checks on the few identified entry points could be a precursor to future vulnerabilities if not addressed. Proactive patching and ongoing security audits are strongly recommended.
Key Concerns
- Unpatched medium severity CVE
- No nonce checks on AJAX
DobsonDev Shortcodes Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
DobsonDev Shortcodes <= 2.1.12 - Authenticated (Contributor+) Stored Cross-Site Scripting
DobsonDev Shortcodes Code Analysis
Bundled Libraries
DobsonDev Shortcodes Attack Surface
Shortcodes 23
WordPress Hooks 5
Maintenance & Trust
DobsonDev Shortcodes Maintenance & Trust
Maintenance Signals
Community Trust
DobsonDev Shortcodes Alternatives
PDF Shortcodes Ultimate
pdf-shortcodes-ultimate
Embed PDF documents in your article or page with this "PDF" shortcode for Shortcodes Ultimate.
PDF Embedder
pdf-embedder
Seamlessly embed PDFs into your content, with customizations and intelligent responsive resizing, and no third-party services or iframes.
PDF Invoices & Packing Slips for WooCommerce
woocommerce-pdf-invoices-packing-slips
Create, print & automatically email PDF or XML Invoices & PDF Packing Slips for WooCommerce orders.
Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer
3d-flipbook-dflip-lite
Dear Flipbook creates PDF Flipbook, 3D Flipbook, PDF viewer, PDF embed for WordPress sites. Create impressive and realistic 3D flipbooks with PDFs.
EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more
embedpress
EmbedPress lets you embed videos, pages, social feeds, embed PDF 3D flipbooks & other content on WordPress without coding & enhance storytelling.
DobsonDev Shortcodes Developer Profile
2 plugins · 110 total installs
How We Detect DobsonDev Shortcodes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dobsondev-shortcodes/css/dobsondev-shortcodes.min.css/wp-content/plugins/dobsondev-shortcodes/js/dobsondev-shortcodes.min.js/wp-content/plugins/dobsondev-shortcodes/js/tinymce-plugin.min.js//maxcdn.bootstrapcdn.com/font-awesome/4.6.3/css/font-awesome.min.css//maxcdn.bootstrapcdn.com/font-awesome/4.4.0/css/font-awesome.min.cssdobsondev-shortcodes/css/dobsondev-shortcodes.min.css?ver=dobsondev-shortcodes/js/dobsondev-shortcodes.min.js?ver=dobsondev-shortcodes/js/tinymce-plugin.min.js?ver=HTML / DOM Fingerprints
dobdev-pdf-container<!-- END .dobdev-pdf-container -->https://api.github.com/repos/<p> Invalid PDF source. Please check your PDF source. </p><p> Please Enter a Owner and Repo for the embedGitHubReadme ShortCode. </p><p> Please Enter a Owner, Repo and Path for the embedGitHubReadme ShortCode. </p>