Gumroad Shortcode Security & Risk Analysis

wordpress.org/plugins/gumroad-shortcode

Simple plugin that shows gumroad products on any page

20 active installs v1.0 PHP + WP 3.0.1+ Updated Oct 23, 2013
apigumroad
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Gumroad Shortcode Safe to Use in 2026?

Generally Safe

Score 85/100

Gumroad Shortcode has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The "gumroad-shortcode" plugin version 1.0 exhibits a generally strong security posture based on the static analysis provided. The absence of dangerous functions, the exclusive use of prepared statements for SQL queries, and the 100% proper output escaping are commendable practices that significantly reduce the risk of common web vulnerabilities. Furthermore, the plugin does not perform file operations, make external HTTP requests, or bundle any libraries, further minimizing its attack surface. The limited attack surface, consisting of a single shortcode with no reported vulnerabilities or known CVEs, contributes to a low-risk profile. However, the lack of explicit nonce and capability checks on the single entry point (the shortcode) represents a potential concern. While the static analysis did not reveal any unsanitized taint flows or critical vulnerabilities, the absence of these protective measures means that if the shortcode's functionality were to become exposed or exploited indirectly, it could potentially lead to unintended consequences without proper authorization or validation. Overall, the plugin demonstrates good coding practices but could be improved by implementing authorization checks on its shortcode.

Key Concerns

  • Missing capability checks on shortcode
  • Missing nonce checks on shortcode
Vulnerabilities
None known

Gumroad Shortcode Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Gumroad Shortcode Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Gumroad Shortcode Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[gumroad] plugin.php:25
WordPress Hooks 1
actionwp_enqueue_scriptsplugin.php:26
Maintenance & Trust

Gumroad Shortcode Maintenance & Trust

Maintenance Signals

WordPress version tested3.6.1
Last updatedOct 23, 2013
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Gumroad Shortcode Developer Profile

zachs

2 plugins · 30 total installs

94
trust score
Avg Security Score
92/100
Avg Patch Time
7 days
View full developer profile
Detection Fingerprints

How We Detect Gumroad Shortcode

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gumroad-shortcode/gumroad-shortcode.php
Script Paths
https://gumroad.com/js/gumroad.js

HTML / DOM Fingerprints

Shortcode Output
<a href=
FAQ

Frequently Asked Questions about Gumroad Shortcode