
Shortcodes for Elementor Security & Risk Analysis
wordpress.org/plugins/shortcode-elementor"Shortcodes for Elementor"lets you effortlessly insert Elementor pages and sections templates anywhere using shortcodes.Create global elements easily!
Is Shortcodes for Elementor Safe to Use in 2026?
Generally Safe
Score 99/100Shortcodes for Elementor has a strong security track record. Known vulnerabilities have been patched promptly.
The "shortcode-elementor" plugin v1.0.8 demonstrates a generally good security posture based on the static analysis, with no identified dangerous functions, raw SQL queries, or file operations. The plugin also shows a commendable effort in output escaping, with a high percentage of outputs properly handled, and it leverages prepared statements for its SQL queries. The vulnerability history indicates a past medium-severity vulnerability, but it is currently patched, which is a positive sign. However, the complete absence of nonce checks and capability checks across all entry points (shortcodes in this case) presents a significant concern. While the attack surface from AJAX and REST API is zero, the two shortcodes remain as potential vectors that could be exploited if not properly secured, especially given the plugin's history. The taint analysis not revealing any issues is positive, but the lack of checks on the shortcodes means that any data processed by them could potentially be vulnerable if malicious input is provided and not adequately sanitized within the shortcode's logic itself.
In conclusion, the "shortcode-elementor" plugin has a solid foundation in terms of avoiding common insecure coding practices like raw SQL and dangerous functions. The past vulnerability being patched is also a good sign. However, the lack of nonce and capability checks on its shortcodes is a notable weakness. While the static analysis did not directly flag exploitable taint flows, the absence of these standard WordPress security mechanisms on user-configurable entry points like shortcodes leaves room for potential authorization bypass or cross-site scripting (XSS) vulnerabilities if the shortcode logic itself doesn't implement sufficient sanitization. The plugin should prioritize implementing nonce and capability checks for its shortcodes to further harden its security.
Key Concerns
- Missing nonce checks on shortcodes
- Missing capability checks on shortcodes
- Medium severity vulnerability history (though patched)
- 78% proper output escaping (room for improvement)
Shortcodes for Elementor Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Shortcodes for Elementor <= 1.0.4 - Authenticated (Contributor+) Post Disclosure
Shortcodes for Elementor Code Analysis
Output Escaping
Shortcodes for Elementor Attack Surface
Shortcodes 2
WordPress Hooks 7
Maintenance & Trust
Shortcodes for Elementor Maintenance & Trust
Maintenance Signals
Community Trust
Shortcodes for Elementor Alternatives
Addons for KingComposer
addons-for-kingcomposer
Impressive modern yet powerful shortcode collections for KingComposer page builder.
WP Foundation Shortcodes
wp-foundation-shortcodes
WP Foundation Shortcodes Plugin makes your ZURB Foundation website to the most powerful framework by styling your content with shortcodes
Amazing Shortcodes for Visual Composer
amazing-shortcodes-for-visual-composer
Amazing Shortcodes For Visual Composer wordpress is an impressive modern shortcode collections.
Shortcodes
bkc-wp-shortcodes
Shortcodes plugin will helps to get option, post meta and other core data using shortcode.
FOUNDATION LIVE SHORTCODES
foundation-live-shortcodes
Add to your content the elements of Zurb Foundation Framework. This plugin is compatible with all themes.
Shortcodes for Elementor Developer Profile
9 plugins · 15K total installs
How We Detect Shortcodes for Elementor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shortcode-elementor/img/icon.pngHTML / DOM Fingerprints
[SHORTCODE_ELEMENTOR id="<?php echo do_shortcode('[SHORTCODE_ELEMENTOR id="[SHORTCODE_ELEMENTOR id=