
Shortcode Generator Security & Risk Analysis
wordpress.org/plugins/shortcode-generatorGenerate as many shortcodes. Keep pages synchronized for split testing, or reuse a specific peice of code on multiple pages.
Is Shortcode Generator Safe to Use in 2026?
Use With Caution
Score 63/100Shortcode Generator has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "shortcode-generator" v1.1 plugin presents a mixed security posture. While the static analysis indicates a minimal attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events, significant concerns arise from the code signals. The presence of the `create_function` dangerous function is a red flag, as it can be a vector for code injection if not handled with extreme care. Furthermore, the complete lack of prepared statements for SQL queries and the very low percentage of properly escaped output (7%) are critical weaknesses, suggesting a high susceptibility to SQL injection and Cross-Site Scripting (XSS) vulnerabilities.
Taint analysis reveals two flows with unsanitized paths, which, while not classified as critical or high, still indicate potential for data leakage or unintended behavior. The vulnerability history, including a medium severity XSS vulnerability from July 2025 that remains unpatched, reinforces these concerns. This pattern of past vulnerabilities and the current unpatched state suggests a recurring issue with input validation and output sanitization within the plugin.
In conclusion, the plugin's apparent low attack surface is overshadowed by fundamental security flaws in its coding practices. The reliance on raw SQL queries, poor output escaping, and the use of dangerous functions, combined with a recent unpatched medium severity vulnerability, paint a picture of a plugin that requires significant attention to its security. While it doesn't exhibit critical or high severity issues in the current static analysis, the underlying technical debt poses a considerable risk.
Key Concerns
- Unpatched medium severity CVE
- Raw SQL queries without prepared statements
- Low percentage of properly escaped output
- Use of dangerous function 'create_function'
- Flows with unsanitized paths found
- Missing nonce checks
- Missing capability checks
Shortcode Generator Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Shortcode Generator <= 1.1 - Reflected Cross-Site Scripting
Shortcode Generator Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Shortcode Generator Attack Surface
WordPress Hooks 2
Maintenance & Trust
Shortcode Generator Maintenance & Trust
Maintenance Signals
Community Trust
Shortcode Generator Alternatives
Apollo13 Framework Extensions
apollo13-framework-extensions
Adds custom post types, shortcodes and some features that are used in themes built on Apollo13 Framework.
Weaver Xtreme Theme Support
weaverx-theme-support
A useful shortcode and widget collection for Weaver Xtreme
Popularis Extra
popularis-extra
Popularis Extra add extra features to Popularis theme like demo import, widgets, shortcodes or Elementor widgets.
Restrict Widgets
restrict-widgets
All in one widgets and sidebars management in WordPress. Allows you to hide or display widgets on specified pages and restrict access for users.
Series
series
Plugin that allows you to collect posts in a series.
Shortcode Generator Developer Profile
2 plugins · 140 total installs
How We Detect Shortcode Generator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shortcode-generator/css/shortcode-generator.css/wp-content/plugins/shortcode-generator/js/shortcode-generator.js/wp-content/plugins/shortcode-generator/js/shortcode-generator.jsshortcode-generator/css/shortcode-generator.css?ver=shortcode-generator/js/shortcode-generator.js?ver=HTML / DOM Fingerprints
widget_manydata-widget-idscg_widget_many<div class="updated fade"><p><strong>