
Grid Shortcodes Security & Risk Analysis
wordpress.org/plugins/grid-shortcodesA responsive and easy-to-use tool for dividing your content in your posts/pages. This ultra-lightweight plugin allows you to put your content in colum …
Is Grid Shortcodes Safe to Use in 2026?
Generally Safe
Score 100/100Grid Shortcodes has a strong security track record. Known vulnerabilities have been patched promptly.
The "grid-shortcodes" plugin v1.1.1 exhibits a mixed security posture. While it demonstrates good practices by not using dangerous functions, performing all SQL queries with prepared statements, and performing file operations or external HTTP requests, there are notable areas of concern. The plugin has 2 shortcodes, and while capability checks are present for both, the static analysis shows that only 50% of the total outputs are properly escaped. This indicates a potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not adequately sanitized before being displayed.
The plugin's vulnerability history includes one known CVE, which was a medium severity Cross-Site Scripting vulnerability. While this vulnerability is currently patched, its presence highlights a historical weakness in input sanitization. The absence of taint analysis flows that are unsanitized or of critical/high severity is a positive sign, but it's crucial to remember that taint analysis is only as effective as the test cases and the depth of the analysis. The total attack surface is low with 2 entry points, and importantly, none are unprotected, which is a strong positive security control.
In conclusion, the "grid-shortcodes" plugin has a generally low attack surface and good SQL hygiene. However, the partial output escaping and the past XSS vulnerability are significant weaknesses that require attention. The plugin has a history of a medium severity XSS, suggesting that input sanitization, especially for shortcodes, needs to be rigorously maintained and tested to prevent future vulnerabilities. The strength lies in its limited entry points and absence of critical code signals, but the weakness in output sanitization for half of its outputs warrants caution.
Key Concerns
- Partial output escaping detected
- Past medium severity XSS vulnerability
Grid Shortcodes Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Grid Shortcodes <= 1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Grid Shortcodes Code Analysis
Output Escaping
Grid Shortcodes Attack Surface
Shortcodes 2
WordPress Hooks 7
Maintenance & Trust
Grid Shortcodes Maintenance & Trust
Maintenance Signals
Community Trust
Grid Shortcodes Alternatives
Perfect Columns
perfect-columns
Add shortcodes to easily create up to 12 equal columns in your pages and posts
q-Shortcodes
q-shortcodes
Send message to email with ajax form
Column Shortcodes
column-shortcodes
Adds shortcodes to easily create columns in your posts or pages.
Lightweight Grid Columns
lightweight-grid-columns
Easily add desktop, tablet and mobile friendly columns to your content using an easy to use shortcode.
Elements For Elementor
nd-elements
The plugin adds some useful elements to the Elementor Page Builder Plugin. All components are full responsive and retina ready.
Grid Shortcodes Developer Profile
8 plugins · 59K total installs
How We Detect Grid Shortcodes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/grid-shortcodes/css/gdc_custom_style.css/wp-content/plugins/grid-shortcodes/img/gsc-mce-icon.png/wp-content/plugins/grid-shortcodes/js/gsc-mce-button.js/wp-content/plugins/grid-shortcodes/js/gsc-mce-button.jsHTML / DOM Fingerprints
gdc_rowgdc_columngdc_innergdc_c<div class="gdc_row"><div class="gdc_column gdc_c<div class="gdc_inner">