Nested Shortcodes by Outerbridge Security & Risk Analysis

wordpress.org/plugins/nested-shortcodes

A small plugin which allows you to use nest shortcodes (i.e. a shortcode within an enclosing shortcode) by implementing a simple do_shortcode filter

1K active installs v1.4 PHP + WP 4.0+ Updated Sep 1, 2022
do_shortcodenestedshortcodestext_widgetthe_content
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Nested Shortcodes by Outerbridge Safe to Use in 2026?

Generally Safe

Score 85/100

Nested Shortcodes by Outerbridge has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the "nested-shortcodes" v1.4 plugin exhibits a very strong security posture. The static analysis reveals a complete absence of common attack vectors like AJAX handlers, REST API routes, shortcodes, and cron events, meaning there are no direct entry points into the plugin for attackers to exploit. Furthermore, the code demonstrates excellent secure coding practices, with no dangerous functions identified, all SQL queries using prepared statements, and all output properly escaped. Taint analysis also shows no unsanitized paths, indicating that data flowing through the plugin is handled securely. The plugin's vulnerability history is equally impressive, with zero recorded CVEs of any severity. This lack of historical vulnerabilities further reinforces the impression of a well-developed and secure plugin. The primary strength lies in its minimal attack surface and robust code hygiene. The only minor point of consideration, and the reason for a slight deduction, is the complete absence of nonce and capability checks. While this is not an issue in the current version due to the lack of entry points, it does mean that if future versions were to introduce any user-facing functionality or entry points, these essential security mechanisms would need to be implemented to maintain this high level of security.

Key Concerns

  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Nested Shortcodes by Outerbridge Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Nested Shortcodes by Outerbridge Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

Nested Shortcodes by Outerbridge Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Nested Shortcodes by Outerbridge Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
filterthe_contentouterbridge-nested-shortcodes.php:33
filterwidget_textouterbridge-nested-shortcodes.php:34
Maintenance & Trust

Nested Shortcodes by Outerbridge Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedSep 1, 2022
PHP min version
Downloads22K

Community Trust

Rating96/100
Number of ratings14
Active installs1K
Developer Profile

Nested Shortcodes by Outerbridge Developer Profile

Outerbridge

3 plugins · 1K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Nested Shortcodes by Outerbridge

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Nested Shortcodes by Outerbridge