Kalimah Shortcodes Security & Risk Analysis

wordpress.org/plugins/kalimah-shortcodes

A premium shortcodes plugin with 40 amazingly designed shortcodes for free!

10 active installs v1.3.4 PHP + WP 4.1+ Updated Nov 1, 2016
accordioncolumnsshortcodesslidertabs
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Kalimah Shortcodes Safe to Use in 2026?

Generally Safe

Score 85/100

Kalimah Shortcodes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The kalimah-shortcodes v1.3.4 plugin presents a mixed security posture. While it exhibits strong practices by not using dangerous functions and performing all SQL queries using prepared statements, several critical security concerns are evident from the static analysis. The presence of two AJAX handlers without any authentication or capability checks creates a significant attack surface. This means any user, regardless of their logged-in status or role, can potentially trigger these handlers, leading to vulnerabilities if they interact with sensitive data or functionality. Furthermore, a very low percentage of output is properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The lack of any recorded vulnerabilities in its history might suggest a lack of targeted attacks or a historically secure codebase, but it should not overshadow the immediate risks identified in the current static analysis.

Key Concerns

  • AJAX handlers without authentication checks
  • Low percentage of properly escaped output
  • No nonce checks on AJAX handlers
  • No capability checks on AJAX handlers
Vulnerabilities
None known

Kalimah Shortcodes Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Kalimah Shortcodes Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
57
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
2
External Requests
3
Bundled Libraries
0

Output Escaping

2% escaped58 total outputs
Attack Surface
2 unprotected

Kalimah Shortcodes Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_kalimah_ajax_update_settingskalimah-shortcodes.php:287
authwp_ajax_kalimah_ajax_update_popularkalimah-shortcodes.php:288
WordPress Hooks 6
actionmedia_buttons_contextkalimah-shortcodes.php:75
actionadmin_footerkalimah-shortcodes.php:79
filterthe_contentkalimah-shortcodes.php:84
actionwp_headkalimah-shortcodes.php:289
actionadmin_enqueue_scriptskalimah-shortcodes.php:290
actionplugins_loadedkalimah-shortcodes.php:292
Maintenance & Trust

Kalimah Shortcodes Maintenance & Trust

Maintenance Signals

WordPress version tested4.6.30
Last updatedNov 1, 2016
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Kalimah Shortcodes Developer Profile

Kalimah Apps

4 plugins · 1K total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Kalimah Shortcodes

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/kalimah-shortcodes/icon-small.png

HTML / DOM Fingerprints

CSS Classes
kalimah-shortcodes-buttonkalimah-shortcodes-button-text
Data Attributes
title='Shortcode Selection'
FAQ

Frequently Asked Questions about Kalimah Shortcodes