
Shadows Security & Risk Analysis
wordpress.org/plugins/shadowsThis is a plugin to add a range of shadow types to a range of objects. Currently supported are images, divs and blockquotes.
Is Shadows Safe to Use in 2026?
Generally Safe
Score 85/100Shadows has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "shadows" v0.3.5 demonstrates a concerning lack of security best practices despite its clean vulnerability history. While the absence of known CVEs and the use of prepared statements for SQL are positive indicators, the analysis reveals significant weaknesses. Specifically, 100% of observed output is not properly escaped, posing a high risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the taint analysis shows flows with unsanitized paths, which could lead to unintended behavior or data exposure if an attacker can influence these paths. The complete lack of nonce and capability checks across all entry points is a critical oversight, leaving the plugin vulnerable to various attacks, including CSRF and unauthorized actions, even with a seemingly small attack surface.
Key Concerns
- 0% output escaping
- Unsanitized paths in taint flows
- 0 capability checks
- 0 nonce checks
Shadows Security Vulnerabilities
Shadows Code Analysis
Output Escaping
Data Flow Analysis
Shadows Attack Surface
WordPress Hooks 3
Maintenance & Trust
Shadows Maintenance & Trust
Maintenance Signals
Community Trust
Shadows Alternatives
Drop Shadow Boxes
drop-shadow-boxes
Highlight important content on your posts and pages inside a box with a drop shadow.
Shadowbox JS
shadowbox-js
Shadowbox is an online media vieiwing application similar to Lightbox and Thickbox but with more functionality. Supports all types of media.
Product Image Hover Effects WOOC – WPSHARE247
product-image-hover-effects-wooc-wpshare247
Add effects when hovering over product Loop woocommerce, display more photo gallery, enlarge product photo gallery Thêm hiệu ứng khi hover sản phẩm L …
Add LightBox & Title
add-lightbox-title
This plugin for WordPress automatically add the rel="lightbox[ID-OF-THE-POST]" and recovers the image title.
RoundIt plugin
roundit
With RoundIt plugin you can set special effects to your pictures that you add in pages or posts. You can make your images Round, set Round Corners, ad …
Shadows Developer Profile
1 plugin · 200 total installs
How We Detect Shadows
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shadows/shadow_curl.png/wp-content/plugins/shadows/shadow_flat.png/wp-content/plugins/shadows/shadow_osx.png/wp-content/plugins/shadows/shadow_osx_small.png/wp-content/plugins/shadows/shadow_osx_top.png/wp-content/plugins/shadows/shadow_osx_small_top.png/wp-content/plugins/shadows/shadow_osx_left.png/wp-content/plugins/shadows/shadow_osx_right.png+1 moreHTML / DOM Fingerprints
shadow_imgshadow_curlshadow_flatshadow_osxshadow_osx_small