
Allow Shortcodes in Text Widgets Security & Risk Analysis
wordpress.org/plugins/parse-shortcodesThis plugin provides the option to enable/disable the shortcodes in the default text widgets along with smilies.
Is Allow Shortcodes in Text Widgets Safe to Use in 2026?
Generally Safe
Score 85/100Allow Shortcodes in Text Widgets has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'parse-shortcodes' v1.0 plugin exhibits a strong overall security posture based on the provided static analysis and vulnerability history. The absence of any recorded vulnerabilities, CVEs, or critical taint flows is a significant positive indicator. The code analysis reveals no dangerous functions, file operations, external HTTP requests, or SQL queries that do not utilize prepared statements, all of which are excellent security practices.
However, a notable concern arises from the output escaping analysis. With 15 total outputs and 0% properly escaped, this represents a significant risk. This lack of proper output sanitization can lead to cross-site scripting (XSS) vulnerabilities if any dynamic content is displayed without sufficient escaping. While the plugin currently has no identified attack surface points (AJAX, REST API, shortcodes, cron events), the potential for XSS through unescaped output remains a critical weakness.
In conclusion, 'parse-shortcodes' v1.0 demonstrates commendable security hygiene in many areas, particularly in its handling of SQL and its lack of external dependencies or dangerous functions. The complete absence of a vulnerability history further strengthens this perception. The paramount weakness, however, is the pervasive lack of output escaping, which introduces a high risk of XSS vulnerabilities and requires immediate attention.
Key Concerns
- 0% output escaping
Allow Shortcodes in Text Widgets Security Vulnerabilities
Allow Shortcodes in Text Widgets Code Analysis
Output Escaping
Allow Shortcodes in Text Widgets Attack Surface
WordPress Hooks 5
Maintenance & Trust
Allow Shortcodes in Text Widgets Maintenance & Trust
Maintenance Signals
Community Trust
Allow Shortcodes in Text Widgets Alternatives
Keep Emoticons as Text
keep-emoticons-as-text
Disables the default WordPress option of converting emoticons to image smilies
Really Disable Emojis
really-disable-emojis
Disables the automatic emojis (smilies) replacement function. Really! :-)
TinyMCE Smiley Button
tinymce-smiley-button
Add Smiley Button to TinyMCE.
Custom Smilies Directory
custom-smilies-directory
Light plugin that tells WordPress to load Smilies from your theme's directory. This allows you to use custom Smilies without loosing them when yo …
Tango/GNOME Smilies
tango-smilies
Replace the blocky default (GIF) smilies with beautiful Tango/GNOME (PNG) smilies.
Allow Shortcodes in Text Widgets Developer Profile
4 plugins · 370 total installs
How We Detect Allow Shortcodes in Text Widgets
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
parse-shortcodes/style.css?ver=parse-shortcodes/script.js?ver=