
Foundation Shortcodes Security & Risk Analysis
wordpress.org/plugins/foundation-shortcodesAdds WordPress shortcode support for Foundation layouts and UI elements - to be used with themes built with Foundation 5.
Is Foundation Shortcodes Safe to Use in 2026?
Generally Safe
Score 85/100Foundation Shortcodes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "foundation-shortcodes" plugin version 1.0.6 exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is a significant strength. Furthermore, the consistent use of prepared statements for all SQL queries and proper output escaping for all identified outputs demonstrates adherence to secure coding practices. The plugin also benefits from a clean vulnerability history with zero recorded CVEs, suggesting a history of secure development and maintenance.
However, there are notable areas for improvement. The plugin has 13 entry points via shortcodes, and the static analysis indicates a complete absence of nonce checks and capability checks across all entry points. This lack of authorization and integrity checks on shortcode usage is a significant concern, as it could potentially allow an attacker to trigger unintended functionality if input to these shortcodes is not properly validated and sanitized on the server-side (though taint analysis found no unsanitized paths). While the taint analysis found no specific issues, the absence of checks on such a large number of shortcodes presents a potential risk if future code changes introduce vulnerabilities.
In conclusion, "foundation-shortcodes" v1.0.6 has several excellent security features, particularly in its handling of SQL and output. The absence of known vulnerabilities is also a positive indicator. The primary weakness lies in the lack of authorization and integrity checks on its shortcode functionality, creating a latent risk that should be addressed to enhance the plugin's overall security.
Key Concerns
- Missing nonce checks on shortcodes
- Missing capability checks on shortcodes
Foundation Shortcodes Security Vulnerabilities
Foundation Shortcodes Code Analysis
Output Escaping
Foundation Shortcodes Attack Surface
Shortcodes 13
WordPress Hooks 3
Maintenance & Trust
Foundation Shortcodes Maintenance & Trust
Maintenance Signals
Community Trust
Foundation Shortcodes Alternatives
WP Shortcode by MyThemeShop
wp-shortcode
WP Shortcode is a premium WP plugin for free, that provides easy to use over 24 shortcodes. You can easily add buttons, alerts, videos and more.
Bootstrap Shortcodes
bootstrap-shortcodes
Wordpress plugin to add shortcodes for Twitter Bootstrap 3.3
Arconix Shortcodes
arconix-shortcodes
Arconix Shortcodes provides a number of useful design elements like buttons, boxes, tabs and toggles to help compliment any website.
Rescue Shortcodes
rescue-shortcodes
A lightweight WordPress shortcodes plugin.
WP Foundation Shortcodes
wp-foundation-shortcodes
WP Foundation Shortcodes Plugin makes your ZURB Foundation website to the most powerful framework by styling your content with shortcodes
Foundation Shortcodes Developer Profile
4 plugins · 90 total installs
How We Detect Foundation Shortcodes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/foundation-shortcodes/foundation-shortcodes.phpHTML / DOM Fingerprints
rowcolumnsmedium-12medium-4buttonflex-videotabstab-title+5 moredata-tabrole="tabpanel"aria-hidden="false"data-accordiondata-reveal-iddata-reveal<div class="row"><div class="- columns">