
Lana Shortcodes Security & Risk Analysis
wordpress.org/plugins/lana-shortcodesBootstrap framework based shortcodes
Is Lana Shortcodes Safe to Use in 2026?
Generally Safe
Score 85/100Lana Shortcodes has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'lana-shortcodes' plugin v1.2.0 exhibits a generally positive security posture based on the static analysis, with several key strengths. All observed SQL queries utilize prepared statements, and all output appears to be properly escaped, indicating good practices in preventing common web vulnerabilities like SQL injection and XSS originating from core data handling. The absence of file operations, external HTTP requests, and dangerous functions further reduces the potential for exploitation. However, a significant concern arises from the complete lack of nonce checks and capability checks across its attack surface, which consists of five shortcodes. This oversight leaves these entry points vulnerable to CSRF attacks and potential unauthorized access if any shortcode functionality performs sensitive actions. The plugin's vulnerability history, while currently showing no unpatched CVEs, includes one past medium-severity vulnerability categorized as Cross-site Scripting. This historical context, combined with the current lack of nonce/capability checks, suggests a pattern where input sanitization and authorization might have been insufficient in the past, and a similar oversight could exist in the shortcode handling. In conclusion, while the code demonstrates good output escaping and secure SQL practices, the absence of crucial authorization and anti-CSRF mechanisms for its shortcodes represents a significant security weakness that needs immediate attention.
Key Concerns
- Missing nonce checks on shortcodes
- Missing capability checks on shortcodes
- Past medium severity XSS vulnerability
Lana Shortcodes Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Lana Shortcodes <= 1.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Lana Shortcodes Release Timeline
Lana Shortcodes Code Analysis
Output Escaping
Lana Shortcodes Attack Surface
Shortcodes 5
WordPress Hooks 9
Maintenance & Trust
Lana Shortcodes Maintenance & Trust
Maintenance Signals
Community Trust
Lana Shortcodes Alternatives
Bootstrap for Contact Form 7
bootstrap-for-contact-form-7
This plugin modifies the output of the popular Contact Form 7 plugin to be styled in compliance with themes using the Bootstrap CSS framework.
Bootstrap Blocks
wp-bootstrap-blocks
Bootstrap Gutenberg Blocks for WordPress. This plugin adds Bootstrap components and layout options as Gutenberg blocks.
Contact Form Clean and Simple
clean-and-simple-contact-form-by-meg-nicholas
A clean and simple contact form with flexible CSS framework support.
bSlider – Create Responsive Image, Post, Product, and Video Sliders
b-slider
bSlider is a WordPress slider plugin that lets you create responsive image, post, product, and video carousels using the Gutenberg block & shortcode.
Genesis Widget Column Classes
genesis-widget-column-classes
Adds Genesis column classes to widgets.
Lana Shortcodes Developer Profile
15 plugins · 4K total installs
How We Detect Lana Shortcodes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lana-shortcodes/assets/css/lana-shortcodes-admin.min.css/wp-content/plugins/lana-shortcodes/assets/libs/bootstrap/v3/css/bootstrap.min.css/wp-content/plugins/lana-shortcodes/assets/libs/bootstrap/v4/css/bootstrap.min.css/wp-content/plugins/lana-shortcodes/assets/libs/popper/Popper.min.js/wp-content/plugins/lana-shortcodes/assets/libs/bootstrap/v3/js/bootstrap.min.js/wp-content/plugins/lana-shortcodes/assets/libs/bootstrap/v4/js/bootstrap.min.js/wp-content/plugins/lana-shortcodes/assets/libs/popper/popper.min.jslana-shortcodes/assets/css/lana-shortcodes-admin.min.css?ver=lana-shortcodes/assets/libs/bootstrap/v3/css/bootstrap.min.css?ver=lana-shortcodes/assets/libs/bootstrap/v4/css/bootstrap.min.css?ver=lana-shortcodes/assets/libs/bootstrap/v3/js/bootstrap.min.js?ver=lana-shortcodes/assets/libs/bootstrap/v4/js/bootstrap.min.js?ver=HTML / DOM Fingerprints
lana-shortcodes-settings-group Lana Shortcodes Modifiable constants Language load+19 morelana_shortcodes_bootstrap_loadlana_shortcodes_bootstrap_version