
Shortcode Security & Risk Analysis
wordpress.org/plugins/shortcodeShortcode is a plugin that adds several useful shortcodes that you can use in your blog posts and pages.
Is Shortcode Safe to Use in 2026?
Use With Caution
Score 63/100Shortcode has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "shortcode" plugin version 0.8.1 exhibits a mixed security posture. On the positive side, the static analysis reveals no dangerous functions, file operations, or external HTTP requests. Notably, all identified output is properly escaped, and the plugin does not bundle any libraries, which can sometimes be a source of vulnerabilities. The attack surface, while comprising 32 shortcodes, is reported as having no unprotected entry points, which is a good sign for direct code execution risks from the outside.
Key Concerns
- Unpatched medium severity CVE
- Raw SQL queries without prepared statements
- No nonce checks on entry points
- No capability checks on entry points
Shortcode Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Shortcode <= 0.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Shortcode Code Analysis
SQL Query Safety
Output Escaping
Shortcode Attack Surface
Shortcodes 32
Maintenance & Trust
Shortcode Maintenance & Trust
Maintenance Signals
Community Trust
Shortcode Alternatives
FHDCU Dynamic Counter Update
dynamic-counter-update
A dynamic counter plugin that increments by a random value every minute and saves it in the database for display anywhere on your site.
Count Shortcode
count-shortcode
Shortcode to count number of posts that match a given set of criteria; provides link to query to display list of matching posts
Total Views
total-views
Count total page views on your WordPress site and display them with a simple shortcode. Customizable label, styles, and editable page views.
GA Google Analytics – Connect Google Analytics to WordPress
ga-google-analytics
Adds Google Analytics tracking code to your WordPress site. Supports many tracking features.
WP Shortcodes Plugin — Shortcodes Ultimate
shortcodes-ultimate
A comprehensive collection of visual components for your site
Shortcode Developer Profile
3 plugins · 910 total installs
How We Detect Shortcode
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
archive-list