
Dynamic Text Security & Risk Analysis
wordpress.org/plugins/dynamic-textDynamic Text is a localization plugin that allows you to have dynamic text and content on your Wordpress pages and posts. To use this plugin, set an …
Is Dynamic Text Safe to Use in 2026?
Generally Safe
Score 85/100Dynamic Text has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "dynamic-text" plugin v2.1.2 presents a generally positive security posture with several key strengths. Notably, the absence of any known vulnerabilities (CVEs) and the fact that its single SQL query utilizes prepared statements are excellent indicators of good development practices. The plugin also reports zero external HTTP requests and file operations, further reducing its attack surface. However, a significant concern arises from the lack of output escaping on all identified outputs. This means any data rendered by the plugin, especially if it originates from user input or external sources, is vulnerable to cross-site scripting (XSS) attacks. While the taint analysis shows no critical or high severity flows, the complete lack of escaping on all outputs is a substantial risk that should be addressed promptly. The plugin also has zero nonce checks, which, when combined with the lack of explicit permission callbacks on its single shortcode entry point (though not explicitly stated as unprotected, the absence of explicit checks is a concern), could potentially lead to unauthorized actions if the shortcode's functionality were to be exploited.
Key Concerns
- No output escaping on any rendered output
- No nonce checks implemented
- No explicit permission callback for shortcode
Dynamic Text Security Vulnerabilities
Dynamic Text Code Analysis
SQL Query Safety
Output Escaping
Dynamic Text Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
Dynamic Text Maintenance & Trust
Maintenance Signals
Community Trust
Dynamic Text Alternatives
Hide Broken Shortcodes
hide-broken-shortcodes
Prevent broken shortcodes from appearing in posts and pages.
Website Content in Page or Post – Embed website content in posts and pages
show-website-content-in-wordpress-page-or-post
Fetches the content of another webpage or URL to display inside the current post or page.
PG Context Sidebar
pg-context-sidebar
Show different content in the sidebar for each page or post - great for emphasising related offers, ideas, or quotes
BNS Inline Asides
bns-inline-asides
This plugin will allow you to style sections of the post, or page, content with added emphasis by leveraging a style element from the active theme.
Timed content show or hide
timed-content-show-or-hide
This plugin show or hide the content after a specified time.
Dynamic Text Developer Profile
1 plugin · 10 total installs
How We Detect Dynamic Text
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
[dynamic_text domain='']