
MW Theme URI Shortcode Security & Risk Analysis
wordpress.org/plugins/mw-theme-uri-shortcodeMW Theme URI Shortcode to make a shortcord outputting theme directory uri.
Is MW Theme URI Shortcode Safe to Use in 2026?
Generally Safe
Score 85/100MW Theme URI Shortcode has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "mw-theme-uri-shortcode" v0.1 plugin exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by exclusively using prepared statements for all SQL queries and has no recorded vulnerability history, indicating a potentially well-maintained codebase to date. Furthermore, it avoids dangerous functions, file operations, and external HTTP requests, which are common vectors for exploitation.
However, significant concerns arise from the static analysis, particularly regarding output escaping. With 100% of its two identified outputs lacking proper escaping, this presents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. Attackers could potentially inject malicious scripts through the shortcodes, leading to unauthorized actions or data theft within the WordPress environment. The absence of nonce checks on AJAX handlers, while there are no AJAX handlers currently, would become a concern if any were introduced without proper security measures.
Despite the lack of historical vulnerabilities, the critical issue of unescaped output poses an immediate and severe threat. While the plugin has a small attack surface and no known CVEs, the current state of output handling significantly undermines its overall security. It is strongly recommended to address the output escaping issues promptly to mitigate the risk of XSS.
Key Concerns
- Unescaped output detected
MW Theme URI Shortcode Security Vulnerabilities
MW Theme URI Shortcode Release Timeline
MW Theme URI Shortcode Code Analysis
Output Escaping
MW Theme URI Shortcode Attack Surface
Shortcodes 3
WordPress Hooks 4
Maintenance & Trust
MW Theme URI Shortcode Maintenance & Trust
Maintenance Signals
Community Trust
MW Theme URI Shortcode Alternatives
Nexter Extension – Security, Performance, Code Snippets & Site Toolkit
nexter-extension
Replace 50+ WordPress Plugins: Free Theme Builder, Code Snippets, Image Optimizer (WebP/AVIF), SMTP Email, Security Hardening, Performance & More
Simple Divi Shortcode
simple-divi-shortcode
Insert DIVI Library item inside module content or inside a php template by using a shortcode.
Log cleaner for Solid Security
log-cleaner-for-ithemes-security
Restores the ability to manually delete Solid Security logs from the database.
Weaver Xtreme Theme Support
weaverx-theme-support
A useful shortcode and widget collection for Weaver Xtreme
Weaver Show Posts
show-posts
Show Posts in a Page via shortcode for any theme
MW Theme URI Shortcode Developer Profile
12 plugins · 131K total installs
How We Detect MW Theme URI Shortcode
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mw-theme-uri-shortcode/js/editor_plugin.js/wp-content/plugins/mw-theme-uri-shortcode/js/editor_plugin.jsHTML / DOM Fingerprints
template_directorystylesheet_directory[theme_directory][template_directory_uri][stylesheet_directory_uri]