
PixCodes Security & Risk Analysis
wordpress.org/plugins/pixcodesPixCodes offers you a nice interface to add shortcodes into editor.
Is PixCodes Safe to Use in 2026?
Generally Safe
Score 85/100PixCodes has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The pixcodes plugin version 2.3.7 exhibits a mixed security posture. On the positive side, it demonstrates good practices by having no dangerous functions, all SQL queries use prepared statements, and it doesn't perform file operations or external HTTP requests. The absence of critical and high severity vulnerabilities in its history is also reassuring. However, there are notable areas of concern. The plugin has a significant attack surface with 26 entry points, and critically, one AJAX handler lacks authentication checks. Furthermore, a substantial percentage (41%) of output is not properly escaped, which directly correlates with its past medium-severity Cross-Site Scripting (XSS) vulnerability. While no taint flows were detected in this analysis, the combination of an unprotected AJAX handler and insufficient output escaping presents a clear risk of XSS attacks if an attacker can trigger that specific AJAX handler.
Key Concerns
- Unprotected AJAX handler detected
- Significant percentage of unescaped output
- Past medium severity XSS vulnerability
- Bundled library (Select2) may be outdated
PixCodes Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
PixCodes <= 2.3.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
PixCodes Release Timeline
PixCodes Code Analysis
Bundled Libraries
Output Escaping
PixCodes Attack Surface
AJAX Handlers 1
Shortcodes 25
WordPress Hooks 14
Maintenance & Trust
PixCodes Maintenance & Trust
Maintenance Signals
Community Trust
PixCodes Alternatives
Rescue Shortcodes
rescue-shortcodes
A lightweight WordPress shortcodes plugin.
Kalimah Shortcodes
kalimah-shortcodes
A premium shortcodes plugin with 40 amazingly designed shortcodes for free!
Column Shortcodes
column-shortcodes
Adds shortcodes to easily create columns in your posts or pages.
Meks Flexible Shortcodes
meks-flexible-shortcodes
Add some cool elements to your post/page content with flexible shortcodes.
Arconix Shortcodes
arconix-shortcodes
Arconix Shortcodes provides a number of useful design elements like buttons, boxes, tabs and toggles to help compliment any website.
PixCodes Developer Profile
8 plugins · 37K total installs
How We Detect PixCodes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pixcodes/css/base.css/wp-content/plugins/pixcodes/js/select2/select2.js/wp-content/plugins/pixcodes/js/add_shortcode.js/wp-content/plugins/pixcodes/js/select2/select2.js/wp-content/plugins/pixcodes/js/add_shortcode.jsHTML / DOM Fingerprints
window.wpgrade_shortcodes_data