
Gleam Shortcodes Security & Risk Analysis
wordpress.org/plugins/gleam-shortcodesAdd a simple list of shortcodes to WordPress in order to display the current user information.
Is Gleam Shortcodes Safe to Use in 2026?
Generally Safe
Score 85/100Gleam Shortcodes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "gleam-shortcodes" v1.0 plugin exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, file operations, external HTTP requests, and the exclusive use of prepared statements for SQL queries are positive indicators. Furthermore, the fact that all output is properly escaped and there are no identified taint flows with unsanitized paths suggests that the plugin is not inherently introducing common vulnerabilities.
However, the analysis does highlight some areas for concern. The plugin has a total of 7 entry points through shortcodes, but none of them appear to have any form of authentication or capability checks. While the static analysis reports 0 unprotected entry points, this is a contradiction that needs further investigation. The lack of nonce checks on these shortcodes, if they are indeed unprotected as implied by the entry point count without explicit auth checks, could leave the plugin susceptible to Cross-Site Request Forgery (CSRF) attacks or unintended actions if these shortcodes perform sensitive operations.
The vulnerability history being completely clear is a significant strength, indicating a history of secure development or at least no publicly disclosed vulnerabilities. However, the lack of specific security checks (like capability checks or nonce checks) on the shortcodes is a potential weakness that could lead to future vulnerabilities, even if none are present currently.
Key Concerns
- Shortcodes lack capability/auth checks
- Shortcodes lack nonce checks
Gleam Shortcodes Security Vulnerabilities
Gleam Shortcodes Code Analysis
Gleam Shortcodes Attack Surface
Shortcodes 7
Maintenance & Trust
Gleam Shortcodes Maintenance & Trust
Maintenance Signals
Community Trust
Gleam Shortcodes Alternatives
User Shortcodes
user-shortcodes
Add a simple list of shortcodes to WordPress in order to display the current user information.
User Role Editor
user-role-editor
User Role Editor WordPress plugin makes user roles and capabilities changing easy. Edit/add/delete WordPress user roles and capabilities.
Simple History – Track, Log, and Audit WordPress Changes
simple-history
Track changes and user activities on your WordPress site. See who created a page, uploaded an attachment, and more, for a complete audit trail.
WP Activity Log
wp-security-audit-log
The #1 user-rated activity log plugin for event logging, activity monitoring and change tracking.
Activity Log – Monitor & Record User Changes
aryo-activity-log
This top rated Activity Log plugin helps you monitor & log all changes and actions on your WordPress site, so you can remain secure and organized.
Gleam Shortcodes Developer Profile
1 plugin · 10 total installs
How We Detect Gleam Shortcodes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
[displayusers_meta][display_firstname][display_lastname][display_displayname]