
Shortcode Mastery Security & Risk Analysis
wordpress.org/plugins/shortcode-mastery-liteShortcode Mastery аllows you to create shortcodes with rich customization options and unlimited number of default parameters.
Is Shortcode Mastery Safe to Use in 2026?
Generally Safe
Score 85/100Shortcode Mastery has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The shortcode-mastery-lite plugin v2.0.0 exhibits a generally strong security posture with no known historical vulnerabilities. The static analysis indicates good practices in several areas, including a robust number of nonce and capability checks, and a moderate percentage of SQL queries utilizing prepared statements. The absence of external HTTP requests and zero recorded CVEs are significant strengths.
However, the analysis does reveal areas of concern. Notably, 54% of output escaping is not properly done, which could lead to cross-site scripting (XSS) vulnerabilities if malicious input is not handled correctly. Additionally, three taint flows were found with unsanitized paths, and one is of high severity, suggesting a potential risk of path traversal or other file system related attacks if these flows are triggered with user-supplied input.
While the attack surface is small and all identified entry points have some form of authentication, the presence of unsanitized paths in the taint analysis, coupled with less than ideal output escaping, presents a moderate risk. The plugin's clean vulnerability history is reassuring, but the identified code signals warrant careful attention to mitigate potential weaknesses.
Key Concerns
- High severity taint flow with unsanitized path
- Significant portion of outputs not properly escaped
- Taint flows with unsanitized paths detected
- SQL queries with insufficient prepared statement usage
Shortcode Mastery Security Vulnerabilities
Shortcode Mastery Release Timeline
Shortcode Mastery Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Shortcode Mastery Attack Surface
AJAX Handlers 1
WordPress Hooks 26
Maintenance & Trust
Shortcode Mastery Maintenance & Trust
Maintenance Signals
Community Trust
Shortcode Mastery Alternatives
Column Shortcodes
column-shortcodes
Adds shortcodes to easily create columns in your posts or pages.
Apollo13 Framework Extensions
apollo13-framework-extensions
Adds custom post types, shortcodes and some features that are used in themes built on Apollo13 Framework.
Futurio Extra
futurio-extra
Futurio Extra add extra features to Futurio theme like widgets, WooCommerce options, Elementor widgets, one click demo import and much more.
ND Shortcodes
nd-shortcodes
The plugin adds some useful components to your page builder ( Elementor or WP Bakery Page Builder ). All components are full responsive and retina rea …
Contact Form 7 Shortcode Enabler
contact-form-7-shortcode-enabler
This plugin enables the usage of external shortcodes inside Contact Form 7 Forms.
Shortcode Mastery Developer Profile
1 plugin · 10 total installs
How We Detect Shortcode Mastery
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shortcode-mastery-lite/assets/css/backend.css/wp-content/plugins/shortcode-mastery-lite/assets/css/backend.min.css/wp-content/plugins/shortcode-mastery-lite/assets/css/frontend.css/wp-content/plugins/shortcode-mastery-lite/assets/css/frontend.min.css/wp-content/plugins/shortcode-mastery-lite/assets/js/backend.js/wp-content/plugins/shortcode-mastery-lite/assets/js/backend.min.js/wp-content/plugins/shortcode-mastery-lite/assets/js/frontend.js/wp-content/plugins/shortcode-mastery-lite/assets/js/frontend.min.js+8 more/wp-content/plugins/shortcode-mastery-lite/assets/js/backend.js/wp-content/plugins/shortcode-mastery-lite/assets/js/backend.min.js/wp-content/plugins/shortcode-mastery-lite/assets/js/frontend.js/wp-content/plugins/shortcode-mastery-lite/assets/js/frontend.min.js/wp-content/plugins/shortcode-mastery-lite/assets/css/backend.css?ver=/wp-content/plugins/shortcode-mastery-lite/assets/css/frontend.css?ver=/wp-content/plugins/shortcode-mastery-lite/assets/js/backend.js?ver=/wp-content/plugins/shortcode-mastery-lite/assets/js/frontend.js?ver=HTML / DOM Fingerprints
sm-editor-container<!-- Shortcode Mastery --><!-- Shortcode Mastery Elementor -->data-sm-iddata-sm-titleShortcodeMasteryShortcodeMasteryData<div class="sm-shortcode-output"><div class="sm-elementor-widget-container">