Hide Broken Shortcodes Security & Risk Analysis

wordpress.org/plugins/hide-broken-shortcodes

Prevent broken shortcodes from appearing in posts and pages.

400 active installs v1.9.4 PHP + WP 2.5+ Updated Oct 10, 2021
contentpagepostshortcodeshortcodes
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Hide Broken Shortcodes Safe to Use in 2026?

Generally Safe

Score 85/100

Hide Broken Shortcodes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The plugin "hide-broken-shortcodes" v1.9.4 exhibits a strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface. Furthermore, the code analysis shows no dangerous functions, all SQL queries use prepared statements, and all output is properly escaped. There are no file operations or external HTTP requests, and crucially, no indications of missing nonce or capability checks, nor any bundled libraries that could introduce vulnerabilities.

The taint analysis also reveals no concerning data flows, with zero flows found with unsanitized paths across all severity levels. The vulnerability history is entirely clean, with no known CVEs, unpatched vulnerabilities, or recorded common vulnerability types. This indicates a history of secure development and maintenance for this plugin.

While the lack of detected vulnerabilities and the clean code signals are highly positive, the complete absence of certain security mechanisms like nonce and capability checks, combined with a zero-count for attack surface entry points, could be interpreted in two ways. It might signify an exceptionally lean and well-secured plugin, or it could indicate that the analysis tools did not identify any features that would necessitate these checks. Given the overall clean report, the former is more likely, suggesting a robustly designed plugin. The primary strength is the lack of exploitable code and a clean history, with no apparent weaknesses in the provided data.

Vulnerabilities
None known

Hide Broken Shortcodes Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Hide Broken Shortcodes Release Timeline

v1.9.4Current
v1.9.3
v1.9.2
v1.9.1
v1.9
v1.8.2
v1.8.1
v1.8
v1.7.1
v1.7
v1.6.3
v1.6.2
v1.6.1
v1.6
v1.5
v1.4
v1.3.1
v1.3
v1.2
v1.1
Code Analysis
Analyzed Mar 16, 2026

Hide Broken Shortcodes Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Hide Broken Shortcodes Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionplugins_loadedhide-broken-shortcodes.php:177
Maintenance & Trust

Hide Broken Shortcodes Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedOct 10, 2021
PHP min version
Downloads26K

Community Trust

Rating90/100
Number of ratings10
Active installs400
Developer Profile

Hide Broken Shortcodes Developer Profile

Scott Reilly

63 plugins · 92K total installs

71
trust score
Avg Security Score
88/100
Avg Patch Time
374 days
View full developer profile
Detection Fingerprints

How We Detect Hide Broken Shortcodes

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Hide Broken Shortcodes