
Shortcode Query Posts By Selected Category Security & Risk Analysis
wordpress.org/plugins/shortcode-query-posts-by-selected-categoryShow a list of posts in a selected category,the number of posts to show is a value of a property of the short code.
Is Shortcode Query Posts By Selected Category Safe to Use in 2026?
Generally Safe
Score 85/100Shortcode Query Posts By Selected Category has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "shortcode-query-posts-by-selected-category" plugin v1.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for SQL queries, showing no dangerous functions, file operations, or external HTTP requests. Furthermore, its limited attack surface, with only one shortcode and no unprotected entry points, is commendable. The absence of known vulnerabilities in its history is also a positive indicator of its development and maintenance.
However, significant concerns arise from the lack of output escaping. With two output points analyzed and 0% properly escaped, this presents a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any data displayed through the shortcode that is not strictly controlled by the administrator could potentially be exploited. Additionally, the absence of nonce and capability checks for the shortcode, while not directly indicated as a vulnerability in the taint analysis (which found no flows), means that the shortcode's execution is not protected against unauthorized use or potential abuse, especially if the output is vulnerable.
Key Concerns
- Output is not properly escaped
- No capability checks on shortcode
- No nonce checks on shortcode
Shortcode Query Posts By Selected Category Security Vulnerabilities
Shortcode Query Posts By Selected Category Code Analysis
Output Escaping
Shortcode Query Posts By Selected Category Attack Surface
Shortcodes 1
Maintenance & Trust
Shortcode Query Posts By Selected Category Maintenance & Trust
Maintenance Signals
Community Trust
Shortcode Query Posts By Selected Category Alternatives
Extra Shortcodes
extra-shortcodes
[extra_archives], [extra_taxonomies], [bloginfo show="name"], [date format="l jS \of F Y"], [date_i18n], [time]
Links shortcode
links-shortcode
The plugin provides the shortcode 'links'. This shortcode shows all links having specified characteristics, following a specified template.
Taxonomy List
taxonomy-list
This plugin help you to display any taxonomy terms by using shortcode. you can use the shortcode any where like in pages, post, widgets.
Category Shortcode
category-shortcode-w-generator
Plugin adds shortcode capability for adding posts by category to a page.
Breadcrumbs Shortcode
breadcrumbs-shortcode
[ ✅ 𝐒𝐄𝐂𝐔𝐑𝐄 𝐏𝐋𝐔𝐆𝐈𝐍𝐒 b𝓎 𝒫𝓊𝓋𝑜𝓍 ] Show breadcrumbs for posts, pages and categories
Shortcode Query Posts By Selected Category Developer Profile
12 plugins · 1K total installs
How We Detect Shortcode Query Posts By Selected Category
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
widget_titleslnet_latest_news_listslnet-recent-postrecent-post-titleCustom shortcode for widget by Suoling.net 2013.11.11<h5 class="widget_title"><ul class="slnet_latest_news_list"><li class="slnet-recent-post"><a href="