
Extra Shortcodes Security & Risk Analysis
wordpress.org/plugins/extra-shortcodes[extra_archives], [extra_taxonomies], [bloginfo show="name"], [date format="l jS \of F Y"], [date_i18n], [time]
Is Extra Shortcodes Safe to Use in 2026?
Use With Caution
Score 63/100Extra Shortcodes has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "extra-shortcodes" plugin v2.2 exhibits a mixed security posture. On the positive side, the static analysis reveals no dangerous functions, all SQL queries are properly prepared, and all outputs are correctly escaped. There are no file operations or external HTTP requests, and the absence of taint flows with unsanitized paths is also a strong indicator of secure coding practices. However, there are significant concerns regarding the lack of explicit authorization checks.
The plugin's attack surface consists entirely of 18 shortcodes, none of which have explicit nonce or capability checks. While this is a positive that there are no unprotected entry points in the analyzed AJAX handlers and REST API routes, the shortcodes represent a substantial blind spot for security. The vulnerability history shows one known medium-severity CVE for Cross-Site Scripting (XSS), which was last patched on 2025-12-31. The fact that this vulnerability is currently unpatched is a critical issue and suggests a lack of ongoing maintenance or a delayed response to security advisories.
In conclusion, while the plugin demonstrates good practices in areas like SQL preparation and output escaping, the complete absence of authorization checks on shortcodes and the presence of an unpatched medium-severity XSS vulnerability introduce significant risks. The shortcodes, as a primary entry point, should have robust security measures in place to prevent potential abuse. The unpatched vulnerability is a direct and present danger to users of this plugin.
Key Concerns
- Unpatched Medium Severity CVE
- Shortcodes lack nonce/capability checks
Extra Shortcodes Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Extra Shortcodes <= 2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Extra Shortcodes Release Timeline
Extra Shortcodes Code Analysis
Output Escaping
Extra Shortcodes Attack Surface
Shortcodes 18
WordPress Hooks 1
Maintenance & Trust
Extra Shortcodes Maintenance & Trust
Maintenance Signals
Community Trust
Extra Shortcodes Alternatives
Category Archives Block
category-archives-block
Displays a monthly or yearly archive of posts for one or more specific categories.
Clean My Archives
clean-my-archives
An easy-to-use shortcode for displaying post archives on your site.
Custom Query Blocks
post-type-archive-mapping
Map your archives to pages. Map 404 and term archives as well.
Posts per Cat
posts-per-cat
Group recent posts by category and show them inside boxes organized to columns.
AW WordPress Yearly Category Archives
aw-yearly-category-archives
This plugin will allow for yearly archives of specific categories from all post types and "Posts".
Extra Shortcodes Developer Profile
14 plugins · 128K total installs
How We Detect Extra Shortcodes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/extra-shortcodes/extra-shortcodes.phpHTML / DOM Fingerprints
Powered by Extra Shortcodes wordpress.org/plugins/extra-shortcodes/<ul></ul>