
Documents Shortcode Security & Risk Analysis
wordpress.org/plugins/documents-shortcodeA [documents] shortcode which will display a list of attached files, with file type icons, and linked to the files for easy downloading.
Is Documents Shortcode Safe to Use in 2026?
Generally Safe
Score 85/100Documents Shortcode has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "documents-shortcode" v1.0.1 plugin exhibits a strong security posture based on the provided static analysis. The plugin demonstrates excellent coding practices by utilizing prepared statements for all SQL queries and ensuring proper output escaping, leaving no identified vulnerabilities in these critical areas. Furthermore, the absence of file operations, external HTTP requests, and bundled libraries further minimizes the potential attack surface. The plugin also shows no history of recorded vulnerabilities, suggesting a consistently secure development and maintenance process.
However, a notable concern arises from the complete lack of nonce checks and capability checks. While the current attack surface is limited to a single shortcode, this absence leaves the plugin vulnerable to potential cross-site request forgery (CSRF) attacks if the shortcode's functionality were to be extended or if it handles user-submitted data in the future. The lack of these fundamental security checks, even with a minimal attack surface, represents a weakness that should be addressed to ensure robust security.
Key Concerns
- Missing nonce checks
- Missing capability checks
Documents Shortcode Security Vulnerabilities
Documents Shortcode Release Timeline
Documents Shortcode Code Analysis
Documents Shortcode Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
Documents Shortcode Maintenance & Trust
Maintenance Signals
Community Trust
Documents Shortcode Alternatives
Simple File List
simple-file-list
Simple File List gives your WordPress website a list of your files which allows your users to open and download them.
AAM Protected Media Files
aam-protected-media-files
Add-on to the free Advanced Access Manager plugin that protects media files from direct access for visitors, roles or users
Get Filesize Shortcode
get-filesize-shortcode
"Get Filesize Shortcode" is a simple shortcode to get filesize of a file( eg. PDF, JPG, PNG ... ).
AJAX File Upload
ajax-file-upload
Fast and easy front-end WordPress file uploader with shortcodes fully extensible
Document Library
document-library
Document Library plugin for handling documents as custom post type and its taxonomies .
Documents Shortcode Developer Profile
5 plugins · 1K total installs
How We Detect Documents Shortcode
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/documents-shortcode/dc_documents.cssHTML / DOM Fingerprints
dc_documents<ul class='dc_documents'><li class=''><a href='