
hk_shortcode Security & Risk Analysis
wordpress.org/plugins/hk-shortcode一个简单的短代码插件
Is hk_shortcode Safe to Use in 2026?
Generally Safe
Score 85/100hk_shortcode has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'hk-shortcode' plugin version 1.0 exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, all SQL queries using prepared statements, and properly escaped outputs are excellent indicators of secure coding practices. Furthermore, the plugin has no recorded vulnerability history, suggesting a history of stable and secure development. The total entry points are limited to shortcodes, and there are no unprotected entry points identified in the static analysis, which is a positive sign for attack surface management.
However, several areas present potential concerns despite the otherwise clean static analysis. The lack of nonce checks and capability checks across all entry points is a significant oversight. While the static analysis found no direct unsanitized taint flows, the absence of these fundamental security mechanisms means that even if the code itself is currently written safely, it is highly susceptible to Cross-Site Request Forgery (CSRF) and privilege escalation vulnerabilities if user-supplied data is ever incorporated into any of the shortcode functionalities without proper validation and authorization. The presence of file operations without explicit context also warrants caution, though its specific risk is not immediately clear without further code review.
In conclusion, 'hk-shortcode' v1.0 benefits from a clean codebase regarding SQL injection and output escaping, and a spotless vulnerability history. However, the complete omission of nonce and capability checks on its entry points represents a critical weakness that could be exploited. The plugin's security is strong in terms of preventing common vulnerabilities like SQL injection, but significantly weakened by its lack of foundational authorization and CSRF protection mechanisms.
Key Concerns
- Missing nonce checks on entry points
- Missing capability checks on entry points
hk_shortcode Security Vulnerabilities
hk_shortcode Release Timeline
hk_shortcode Code Analysis
SQL Query Safety
Output Escaping
hk_shortcode Attack Surface
Shortcodes 16
WordPress Hooks 5
Maintenance & Trust
hk_shortcode Maintenance & Trust
Maintenance Signals
Community Trust
hk_shortcode Alternatives
WP Shortcodes Plugin — Shortcodes Ultimate
shortcodes-ultimate
A comprehensive collection of visual components for your site
MW WP Form
mw-wp-form
MW WP Form is shortcode base contact form plugin. This plugin have many features. For example you can use many validation rules, inquiry data saving, …
Shortcoder — Create Shortcodes for Anything
shortcoder
Create custom "Shortcodes" easily for HTML, JavaScript, CSS code snippets and use the shortcodes within posts, pages & widgets
Display Posts – Easy lists, grids, navigation, and more
display-posts-shortcode
Add a listing of content on your website using a simple shortcode. Filter the results by category, author, and more.
WP Show Posts
wp-show-posts
Add posts to your website from any post type using a simple shortcode.
hk_shortcode Developer Profile
1 plugin · 0 total installs
How We Detect hk_shortcode
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/hk-shortcode/static/css/post.css/wp-content/plugins/hk-shortcode/static/css/addon.css/wp-content/plugins/hk-shortcode/static/lib/font-awesome/css/font-awesome.min.css/wp-content/plugins/hk-shortcode/static/lib/plyr/plyr.css/wp-content/plugins/hk-shortcode/static/lib/highlight/highlight.min.js/wp-content/plugins/hk-shortcode/static/lib/highlight/init.js/wp-content/plugins/hk-shortcode/static/lib/highlight/dark.css/wp-content/plugins/hk-shortcode/static/js/addon.js+5 moreHTML / DOM Fingerprints
button_shortcodebutton_normal_shortcodebutton_panel_shortcodebutton_cloud_shortcodeshortcodenormal_shortcodeclose_buttonshort_code_select+7 moretypehuankong_THEME_PATH<div class="title-plane"><div class="start-plane"<div class="icon-url"