
Mahjong Tiles Security & Risk Analysis
wordpress.org/plugins/mahjong-tilesMahjong Tiles adds a shortcode [tile] that makes adding Mahjong tiles to your posts easy.
Is Mahjong Tiles Safe to Use in 2026?
Generally Safe
Score 100/100Mahjong Tiles has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "mahjong-tiles" v1.0 plugin exhibits a generally positive security posture based on the provided static analysis. The absence of dangerous functions, external HTTP requests, file operations, and SQL queries executed without prepared statements are strong indicators of secure coding practices. The plugin also demonstrates an awareness of WordPress security by including capability checks. The lack of any recorded vulnerabilities or CVEs further reinforces this impression.
However, a significant concern arises from the output escaping. With 100% of identified outputs not being properly escaped, this plugin presents a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any dynamic data rendered by the plugin could be exploited by attackers to inject malicious scripts, potentially leading to session hijacking or unauthorized actions. The absence of nonce checks, while not explicitly flagged as a direct risk due to the lack of AJAX handlers, could become a concern if the plugin were to implement such features in the future without proper checks.
In conclusion, while the "mahjong-tiles" plugin has a strong foundation in secure development by avoiding many common pitfalls, the unescaped output is a critical oversight that significantly increases its risk profile. Addressing the XSS vulnerability should be the top priority to mitigate potential security incidents.
Key Concerns
- Unescaped output detected
Mahjong Tiles Security Vulnerabilities
Mahjong Tiles Code Analysis
Output Escaping
Mahjong Tiles Attack Surface
Shortcodes 2
WordPress Hooks 2
Maintenance & Trust
Mahjong Tiles Maintenance & Trust
Maintenance Signals
Community Trust
Mahjong Tiles Alternatives
WP Shortcodes Plugin — Shortcodes Ultimate
shortcodes-ultimate
A comprehensive collection of visual components for your site
MW WP Form
mw-wp-form
MW WP Form is shortcode base contact form plugin. This plugin have many features. For example you can use many validation rules, inquiry data saving, …
Shortcoder — Create Shortcodes for Anything
shortcoder
Create custom "Shortcodes" easily for HTML, JavaScript, CSS code snippets and use the shortcodes within posts, pages & widgets
Display Posts – Easy lists, grids, navigation, and more
display-posts-shortcode
Add a listing of content on your website using a simple shortcode. Filter the results by category, author, and more.
WP Show Posts
wp-show-posts
Add posts to your website from any post type using a simple shortcode.
Mahjong Tiles Developer Profile
4 plugins · 107K total installs
How We Detect Mahjong Tiles
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mahjong-tiles/tile_images/HTML / DOM Fingerprints
tile<img srcalt="1 bamboo"alt="2 bamboo"alt="3 bamboo"