
Shortcode Callback Security & Risk Analysis
wordpress.org/plugins/shortcode-callbackAdds a [callback] shortcode that can trigger PHP code so you can insert custom/complex things into your pages/posts.
Is Shortcode Callback Safe to Use in 2026?
Generally Safe
Score 85/100Shortcode Callback has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "shortcode-callback" v1.0.0 plugin exhibits a generally positive security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, unescaped output, file operations, external HTTP requests, and any recorded vulnerabilities in its history are all strong indicators of good development practices. The plugin has a minimal attack surface, with only one shortcode identified, and crucially, this entry point is not immediately flagged as unprotected. Taint analysis also shows no critical or high-severity unsanitized paths, further bolstering confidence in its security.
Key Concerns
- No nonce checks detected
- No capability checks detected
Shortcode Callback Security Vulnerabilities
Shortcode Callback Release Timeline
Shortcode Callback Code Analysis
Shortcode Callback Attack Surface
Shortcodes 1
Maintenance & Trust
Shortcode Callback Maintenance & Trust
Maintenance Signals
Community Trust
Shortcode Callback Alternatives
Code Widget
code-widget
Code widget help to add Short Code, PHP Code, HTML, and Simple Text in widget.
URL ShortCodes
url-shortcodes
URL ShortCodes plugin adds support for a basic short codes to use in your post/page editor that produce correct absolute URLs.
Inline Spoilers
inline-spoilers
The plugin allows to create content spoilers with Guttenberg block or simple shortcode.
Remove Orphan Shortcodes
remove-orphan-shortcodes
Quickly remove unused (orphan) shortcode tags from your content.
Uix Shortcodes
uix-shortcodes
Uix Shortcodes brings an amazing set of beautiful and useful elements to your site that lets you do nifty things with very little effort.
Shortcode Callback Developer Profile
4 plugins · 3K total installs
How We Detect Shortcode Callback
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
[callback][callback] Function not callable: [callback] File not found: