
DriveWorks Shortcode – Form Embed Security & Risk Analysis
wordpress.org/plugins/driveworks-shortcode-form-embedUse shortcodes to embed DriveWorks Projects or DriveApps.
Is DriveWorks Shortcode – Form Embed Safe to Use in 2026?
Generally Safe
Score 100/100DriveWorks Shortcode – Form Embed has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The driveworks-shortcode-form-embed plugin version 1.0.2 exhibits a strong security posture based on the provided static analysis and vulnerability history. The code analysis reveals no dangerous functions, all SQL queries use prepared statements, and all output is properly escaped. Crucially, there are no external HTTP requests or file operations, further minimizing the attack surface. The absence of any recorded vulnerabilities, including CVEs, is a significant positive indicator of the plugin's security over time.
While the plugin demonstrates excellent adherence to secure coding practices, a notable concern is the complete absence of nonce checks and capability checks. This means that the single shortcode entry point, while not directly exposed via AJAX or REST API, lacks robust authorization and integrity checks. If the shortcode's functionality involves any sensitive operations or user-specific data manipulation, this oversight could become a significant risk, especially if the plugin's scope expands or if future updates introduce such functionalities without adequate security considerations. However, given the current analysis, the immediate risk is low due to the limited entry points and lack of dangerous code patterns.
Key Concerns
- Missing nonce checks
- Missing capability checks
DriveWorks Shortcode – Form Embed Security Vulnerabilities
DriveWorks Shortcode – Form Embed Code Analysis
DriveWorks Shortcode – Form Embed Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
DriveWorks Shortcode – Form Embed Maintenance & Trust
Maintenance Signals
Community Trust
DriveWorks Shortcode – Form Embed Alternatives
Challonge
challonge
Integrates Challonge, a handy bracket generator, into WordPress.
Advanced iFrame
advanced-iframe
Include content the way YOU like in an iframe that can hide and modify elements, does auto-height, forward parameters and does many, many more...
Insert Pages
insert-pages
Insert Pages lets you embed any WordPress content (e.g., pages, posts, custom post types) into other WordPress content using the Shortcode API.
Spreaker Shortcode
spreaker-shortcode
A simple and easy way to embed Spreaker player into your WordPress blog.
Simple YouTube Responsive
simple-youtube-responsive
Easily embed responsive YouTube videos using a simple shortcode. Lazy load included.
DriveWorks Shortcode – Form Embed Developer Profile
1 plugin · 10 total installs
How We Detect DriveWorks Shortcode – Form Embed
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/driveworks-shortcode-form-embed/script.js/wp-content/plugins/driveworks-shortcode-form-embed/style.csshttps://plugins.driveworkslive.com/DriveWorksLiveIntegrationClient.min.jsdriveworks-shortcode-form-embed/style.css?ver=driveworks-shortcode-form-embed/script.js?ver=HTML / DOM Fingerprints
dw-shortcode-embeddw-is-loadingdw-form-outputdw-embed-loadingdw-embed-messagedw-message-form-completedw-message-form-canceldw-embed-errordata-driveworks-shortcode-embeddata-debugdata-server-urldata-group-aliasdata-project-namedata-drive-app-alias+3 more<div data-driveworks-shortcode-embedclass="dw-shortcode-embed dw-is-loading"data-server-url=data-group-alias=