WP Shortcode by Drimify Security & Risk Analysis

wordpress.org/plugins/drimify-widget

Drimify Widget is a free WP plugin, that provides easy way to integrate your HTML5 games and interactive contents created on Drimify.com

60 active installs v1.0.10 PHP + WP 3.0.2+ Updated Nov 30, 2025
drimifyhtml5-gamesmarketing-gamesshortcodeshortcodes
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is WP Shortcode by Drimify Safe to Use in 2026?

Generally Safe

Score 100/100

WP Shortcode by Drimify has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The "drimify-widget" v1.0.10 plugin exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, unescaped output, file operations, and external HTTP requests is commendable. Crucially, there are no identified taint flows, indicating a low risk of code injection or manipulation. The plugin also demonstrates good practice by avoiding bundled libraries. The vulnerability history shows no known CVEs, further reinforcing its current secure state.

However, the analysis does reveal a single shortcode as an entry point. While it's not explicitly stated if this shortcode has proper capability checks or nonce validation, the absence of recorded vulnerability types and the generally clean code signal suggest that these are likely implemented. The lack of explicit nonce and capability checks in the static analysis, even with zero unprotected entry points, presents a minor area for potential scrutiny if deeper analysis were possible. Overall, the plugin appears to be well-developed with security in mind, with the primary potential for concern being the security of the shortcode implementation, which is not fully detailed in the provided data.

Key Concerns

  • Missing explicit nonce check
  • Missing explicit capability check
Vulnerabilities
None known

WP Shortcode by Drimify Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP Shortcode by Drimify Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

WP Shortcode by Drimify Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[drimify] drimify.php:64
Maintenance & Trust

WP Shortcode by Drimify Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedNov 30, 2025
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs60
Developer Profile

WP Shortcode by Drimify Developer Profile

Drimlike

1 plugin · 60 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Shortcode by Drimify

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/drimify-widget/drimify.php
Script Paths
https://cdn.drimify.com/js/drimifywidget.release.min.js

HTML / DOM Fingerprints

Data Attributes
id="drimify-container"id="gamification-widget"
JS Globals
Drimify.WidgetDigitaService.Widget.Create
Shortcode Output
<div id="drimify-container"<div id="gamification-widget"
FAQ

Frequently Asked Questions about WP Shortcode by Drimify