
Forget About Shortcode Buttons Security & Risk Analysis
wordpress.org/plugins/forget-about-shortcode-buttonsA visual way to add CSS buttons in the rich text editor and to your themes.
Is Forget About Shortcode Buttons Safe to Use in 2026?
Generally Safe
Score 91/100Forget About Shortcode Buttons has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin "forget-about-shortcode-buttons" v2.1.3 exhibits a mixed security posture. On the positive side, the static analysis reveals a very small attack surface, with only one AJAX handler and no exposed REST API routes, shortcodes, or cron events. Crucially, this single AJAX handler appears to be protected by a nonce check, which is a good practice. The code also demonstrates a commitment to secure database interaction with 100% of SQL queries using prepared statements and no file operations or external HTTP requests, further reducing potential attack vectors. However, a significant concern arises from the low percentage of properly escaped output (17%). This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, where untrusted input could be rendered directly into the user's browser, leading to malicious code execution.
Key Concerns
- Low output escaping rate
- Two medium severity historical CVEs
Forget About Shortcode Buttons Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Forget About Shortcode Buttons <= 2.1.2 - Missing Authorization via fasc_buttons
Forget About Shortcode Buttons <= 1.1.1 - Reflected Cross-Site Scripting
Forget About Shortcode Buttons Code Analysis
Output Escaping
Forget About Shortcode Buttons Attack Surface
AJAX Handlers 1
WordPress Hooks 7
Maintenance & Trust
Forget About Shortcode Buttons Maintenance & Trust
Maintenance Signals
Community Trust
Forget About Shortcode Buttons Alternatives
Microthemer Lite – Visual Editor to Customize CSS
microthemer
A visual editor to customize the CSS styling of anything on your site - from Google fonts to responsive layouts.
Visual Editor Custom Buttons
visual-editor-custom-buttons
Visual Editor Custom Buttons lets you add custom buttons to the Wordpress Visual Editor.
Manage TinyMCE Editor
manage-tinymce-editor
Add buttons to TinyMCE, WordPress' default visual editor.
Safer Email Link
safer-email-link
Adds a button to the TinyMCE to wrap an email address with a shortcode using the WordPress antispambot function.
Crazy Pills
crazy-pills
Build buttons, boxes, beautiful lists, and highlight text right from your editor, with live preview.
Forget About Shortcode Buttons Developer Profile
4 plugins · 84K total installs
How We Detect Forget About Shortcode Buttons
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/forget-about-shortcode-buttons/admin/css/forget-about-shortcode-buttons-admin.cssforget-about-shortcode-buttons-admin.css?ver=HTML / DOM Fingerprints
button_fasc_insert_buttonfasc-buttonsfasc_buttonsfasc_save/wp-json/fasc_buttons