
ShortCode – Get Child List Security & Risk Analysis
wordpress.org/plugins/shortcode-get-child-listThis plugin provide two shortcode. Using the shortcode you can easily generate a childpage list, and also a sitemap.
Is ShortCode – Get Child List Safe to Use in 2026?
Generally Safe
Score 85/100ShortCode – Get Child List has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "shortcode-get-child-list" plugin, version 0.4, exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, file operations, external HTTP requests, and the consistent use of prepared statements for SQL queries indicate good coding practices. The fact that 100% of outputs are properly escaped is also a significant strength. Furthermore, the plugin has no recorded vulnerabilities (CVEs) and a clean vulnerability history, which suggests a generally secure development and maintenance process.
However, a key area of concern is the lack of explicit capability checks and nonce checks on its entry points. While the static analysis indicates zero unprotected entry points, the absence of these fundamental WordPress security mechanisms on its two shortcodes means that if any functionality within these shortcodes were to become vulnerable in the future, it could potentially be exploited without the standard WordPress security layers being engaged. The taint analysis showing zero flows analyzed is a neutral observation; it could mean there were no complex data flows to analyze, or that the analysis might not have covered all potential edge cases.
In conclusion, the plugin demonstrates a commendable adherence to secure coding standards for SQL and output handling, and its lack of historical vulnerabilities is positive. The primary weakness lies in the reliance on the shortcode system itself to enforce access controls, rather than explicit capability and nonce checks within the plugin's code. This leaves a potential, albeit currently theoretical, opening for privilege escalation or other attacks if the internal logic of the shortcodes were to be compromised.
Key Concerns
- Missing capability checks on entry points
- Missing nonce checks on entry points
ShortCode – Get Child List Security Vulnerabilities
ShortCode – Get Child List Code Analysis
ShortCode – Get Child List Attack Surface
Shortcodes 2
Maintenance & Trust
ShortCode – Get Child List Maintenance & Trust
Maintenance Signals
Community Trust
ShortCode – Get Child List Alternatives
List Children
list-children
Use an HTML comment to list links of the current page's children or siblings.
List Pages Shortcode
list-pages-shortcode
Introduces the [list-pages], [sibling-pages] and [child-pages] shortcodes for easily displaying a list of pages within a post or page.
Recently Updated Pages and Posts
recently-updated-pages-and-posts
Creates a sidebar widget that lists recently updated pages and posts including newly published items.
List All Pages
list-all-pages
List all pages on a WordPress site for easy browsing and editing.
DMG Related Pages Widget
dmg-related-pages-widget
Widget that displays a list of pages related to the current page in your sidebar. Advanced options allow you to control which pages are shown, add CSS …
ShortCode – Get Child List Developer Profile
1 plugin · 10 total installs
How We Detect ShortCode – Get Child List
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
page-item<ul></ul><div id='sitemap'></div>