
QRCode Security & Risk Analysis
wordpress.org/plugins/doqrcodeA simple plugin to generate QR Code by shortcode for WordPress
Is QRCode Safe to Use in 2026?
Generally Safe
Score 100/100QRCode has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The doqrcode v1.2.2 plugin exhibits a generally good security posture due to its avoidance of dangerous functions, 100% use of prepared statements for SQL queries, and lack of external HTTP requests. The absence of known vulnerabilities in its history is also a positive indicator. However, several significant concerns arise from the static analysis. The most critical issue is the extremely low rate of output escaping (9%), indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. With 11 total outputs and only one properly escaped, a vast majority of dynamic content displayed by the plugin is likely vulnerable. Furthermore, the complete lack of nonce checks and capability checks is alarming, especially given the presence of a shortcode which represents an entry point into the plugin's functionality. This means that any user, regardless of their privileges, could potentially trigger this shortcode, and actions within it might be exploitable without proper authorization verification. The plugin also performs 10 file operations, which, in conjunction with poor output escaping and a lack of authorization checks, could lead to further security risks if not handled with extreme care.
Key Concerns
- Very low output escaping percentage (9%)
- No nonce checks implemented
- No capability checks implemented
- Shortcode as an entry point without auth checks
QRCode Security Vulnerabilities
QRCode Code Analysis
Output Escaping
QRCode Attack Surface
Shortcodes 1
Maintenance & Trust
QRCode Maintenance & Trust
Maintenance Signals
Community Trust
QRCode Alternatives
Barcode Generator for WooCommerce – Show barcodes on products, orders, invoices and other pages
embedding-barcodes-into-product-pages-and-orders
Embed product and order barcodes into web-pages, emails, invoices or any other places on your website.
Wa Qrcode
wa-qr-code-generator
Use Wa QRcode generate to put QR code to you post, page or content area or widget area without editing your theme files
Kaya QR Code Generator
kaya-qr-code-generator
Generate QR Code through Widgets and Shortcodes, without any dependencies.
EAN Barcode Generator for WooCommerce: UPC, ISBN & GTIN Inventory
ean-for-woocommerce
Manage GTINs (EAN, UPC, ISBN, etc.) effortlessly in WooCommerce! Create, save, search, and display EANs easily, with tools for bulk actions, etc.
VietQR
vietqr
Tự động tạo mã QR ngân hàng cho từng đơn hàng. Mã QR sẽ nhúng sẵn số tiền, mã đơn hàng, người mua quét QR xong chỉ cần bấm xác nhận là chuyển xong nga …
QRCode Developer Profile
6 plugins · 8K total installs
How We Detect QRCode
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/doqrcode/phpqrcode.lib.phpHTML / DOM Fingerprints
<img src='data:image/svg+xml;base64,