MindValley Shortcut Framework Security & Risk Analysis

wordpress.org/plugins/mindvalley-shortcut-framework

Collection of Additional Keyboard Shortcuts for Post Editor page.

10 active installs v0.1.2 PHP + WP 3.0.0+ Updated Unknown
editorshortcut
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is MindValley Shortcut Framework Safe to Use in 2026?

Generally Safe

Score 100/100

MindValley Shortcut Framework has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "mindvalley-shortcut-framework" plugin v0.1.2 presents a generally positive initial security posture based on the static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points suggests a limited attack surface. Furthermore, the code signals indicate good practices in SQL query handling, with 100% using prepared statements, and the presence of nonce and capability checks. The taint analysis showing no unsanitized paths or critical/high severity flows is also reassuring.

However, a significant concern arises from the "Output escaping: 11 total outputs, 0% properly escaped" finding. This indicates a high likelihood of Cross-Site Scripting (XSS) vulnerabilities, as unsanitized data displayed to users can be exploited. The vulnerability history also shows no recorded issues, which, while good, could also mean the plugin hasn't been thoroughly tested or subjected to extensive real-world attacks, especially given its low version number. The complete lack of documented vulnerabilities might be due to its limited exposure or a genuinely clean codebase, but the unescaped output is a concrete, actionable risk that needs immediate attention.

Key Concerns

  • Unescaped output found
Vulnerabilities
None known

MindValley Shortcut Framework Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

MindValley Shortcut Framework Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
11
0 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped11 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
the_option_page (mindvalley-shortcut-framework.php:47)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

MindValley Shortcut Framework Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_menumindvalley-shortcut-framework.php:30
actionadmin_footermindvalley-shortcut-framework.php:37
filtertiny_mce_before_initmindvalley-shortcut-framework.php:38
Maintenance & Trust

MindValley Shortcut Framework Maintenance & Trust

Maintenance Signals

WordPress version tested3.0.5
Last updatedUnknown
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

MindValley Shortcut Framework Developer Profile

Mindvalley

7 plugins · 160 total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect MindValley Shortcut Framework

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mindvalley-shortcut-framework/images/control.png/wp-content/plugins/mindvalley-shortcut-framework/images/command.png/wp-content/plugins/mindvalley-shortcut-framework/images/option.png
Script Paths
/wp-content/plugins/mindvalley-shortcut-framework/jquery.client.js/wp-content/plugins/mindvalley-shortcut-framework/jquery.hotkeys.js/wp-content/plugins/mindvalley-shortcut-framework/shortcut_fn.js
Version Parameters
mindvalley-shortcut-framework/jquery.client.js?ver=mindvalley-shortcut-framework/jquery.hotkeys.js?ver=mindvalley-shortcut-framework/shortcut_fn.js?ver=

HTML / DOM Fingerprints

CSS Classes
wrapform-table
Data Attributes
id="prompt-action"id="skip-prompt"name="mv_sc_settings[skip_prompt]"name="mv_sc_settings[keys_bindings][mv_sc_preview_changes]"name="mv_sc_settings[keys_bindings][mv_sc_publish]"name="mv_sc_settings[keys_bindings][mv_sc_save_post]"+2 more
JS Globals
mv_sc_skip_promptmv_sc_preview_changesmv_sc_publishmv_sc_save_postbindTinyMCEKeys
FAQ

Frequently Asked Questions about MindValley Shortcut Framework