
Ragic Shortcode Security & Risk Analysis
wordpress.org/plugins/ragic-shortcodeAllows the use of a special shortcode for embedding Ragic forms.
Is Ragic Shortcode Safe to Use in 2026?
Generally Safe
Score 91/100Ragic Shortcode has a strong security track record. Known vulnerabilities have been patched promptly.
The "ragic-shortcode" plugin v1.3 exhibits a generally positive security posture based on the static analysis. It adheres to several good security practices, notably by not using any dangerous functions, executing all SQL queries with prepared statements, and ensuring all output is properly escaped. Furthermore, it avoids file operations, external HTTP requests, and does not bundle any external libraries, which reduces potential attack vectors. The attack surface is minimal, consisting solely of one shortcode, and importantly, there are no unprotected entry points identified in this analysis. Taint analysis also indicates no critical or high severity flows, suggesting a lack of easily exploitable data handling vulnerabilities within the current code.
However, the plugin's security record is tarnished by its vulnerability history. The presence of one known CVE, even if currently patched, suggests past issues that required remediation. The fact that this vulnerability was of medium severity and related to Cross-site Scripting (XSS) is a concern, as XSS can lead to account takeovers and other serious security breaches. While the current version may be patched, the historical pattern warrants caution. The absence of nonce and capability checks on its single shortcode entry point is also a potential weakness, as it means any user could potentially trigger its functionality, although the lack of other exploitable code signals mitigates this risk significantly in the current version. The lack of these checks on shortcodes could be a future vulnerability if the shortcode's functionality evolves to handle sensitive data or actions.
In conclusion, while "ragic-shortcode" v1.3 demonstrates commendable coding practices in its current implementation, particularly regarding SQL and output handling, its past vulnerability history and the absence of explicit authorization checks on its shortcode are points of concern. The plugin is relatively secure due to its minimal attack surface and good coding hygiene, but users should remain vigilant regarding future updates and the potential for new vulnerabilities, especially given the historical XSS issue. The absence of capability checks on the shortcode is a weakness that, while not currently exploitable due to other code characteristics, represents a risk if the shortcode's functionality changes.
Key Concerns
- Known CVE (medium severity)
- Shortcode lacks capability checks
Ragic Shortcode Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Ragic Shortcode <= 1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Ragic Shortcode Code Analysis
Ragic Shortcode Attack Surface
Shortcodes 1
Maintenance & Trust
Ragic Shortcode Maintenance & Trust
Maintenance Signals
Community Trust
Ragic Shortcode Alternatives
WP Shortcodes Plugin — Shortcodes Ultimate
shortcodes-ultimate
A comprehensive collection of visual components for your site
MW WP Form
mw-wp-form
MW WP Form is shortcode base contact form plugin. This plugin have many features. For example you can use many validation rules, inquiry data saving, …
Shortcoder — Create Shortcodes for Anything
shortcoder
Create custom "Shortcodes" easily for HTML, JavaScript, CSS code snippets and use the shortcodes within posts, pages & widgets
Display Posts – Easy lists, grids, navigation, and more
display-posts-shortcode
Add a listing of content on your website using a simple shortcode. Filter the results by category, author, and more.
WP Show Posts
wp-show-posts
Add posts to your website from any post type using a simple shortcode.
Ragic Shortcode Developer Profile
1 plugin · 80 total installs
How We Detect Ragic Shortcode
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ragic-shortcode/intl/common/load.js/wp-content/plugins/ragic-shortcode/intl/common/loadfts.js//a.hostname/intl/common/load.js?wp//a.hostname/intl/common/loadfts.js?wpragic-shortcode/intl/common/load.js?ver=ragic-shortcode/intl/common/loadfts.js?ver=HTML / DOM Fingerprints
ragic_rawembed * * CONFIGURATION VARIABLES: EDIT BEFORE PASTING INTO YOUR WEBPAGE * * * * DON'T EDIT BELOW THIS LINE * * sandbox="allow-modals allow-forms allow-popups allow-scripts allow-same-origin"ragic_urlragic_featurewebFormVersionIsNew<div id='ragic_webview'></div><div style='height:200;width:300;text-align:center'><h3>There is something wrong with your short code parameter!</h3></div>