
Shortcode Redirect Security & Risk Analysis
wordpress.org/plugins/shortcode-redirectRedirect any post or page — with a native block or a classic shortcode. Optional delay. Optional "redirecting" message. Zero configuration.
Is Shortcode Redirect Safe to Use in 2026?
Generally Safe
Score 99/100Shortcode Redirect has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'shortcode-redirect' plugin version 1.0.03 presents a mixed security posture. On the positive side, the static analysis reveals no dangerous functions, all SQL queries are prepared, there are no file operations or external HTTP requests, and the limited attack surface (one shortcode) does not appear to have immediate unprotected entry points based on the provided data. Taint analysis also shows no critical or high severity flows.
However, several concerns arise. The vulnerability history shows a significant past issue with two medium severity Cross-site Scripting (XSS) vulnerabilities, even though none are currently unpatched. The fact that a recent vulnerability was recorded in August 2025, while the analyzed version is 1.0.03, suggests potential for undiscovered or historical issues. Furthermore, only 40% of output is properly escaped, indicating a potential for XSS vulnerabilities if user-supplied data is rendered without adequate sanitization, especially given the plugin's shortcode functionality which often handles user input.
While the current static analysis and taint analysis don't flag immediate critical issues, the past vulnerability history and the moderate output escaping rate are red flags. The plugin has a track record of XSS, and the current code may still be susceptible if user input is not handled carefully within the shortcode. It's advisable to audit the shortcode implementation thoroughly for any unescaped output that might be rendered in a user's browser.
Key Concerns
- Past medium severity XSS vulnerabilities
- Moderate output escaping (40%)
- No capability checks on shortcode
Shortcode Redirect Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Shortcode Redirect <= 1.0.02 - Authenticated (Contributor+) Stored Cross-Site Scripting
Shortcode Redirect <= 1.0.01 - Cross-Site Scripting
Shortcode Redirect Release Timeline
Shortcode Redirect Code Analysis
Output Escaping
Shortcode Redirect Attack Surface
Shortcodes 1
Maintenance & Trust
Shortcode Redirect Maintenance & Trust
Maintenance Signals
Community Trust
Shortcode Redirect Alternatives
Latest Post Shortcode
latest-post-shortcode
The "Latest Post Shortcode" allows you to create a dynamic content selection from your posts by combining, limiting, and filtering what you need.
Shortcode Preview Block
shortcode-with-preview-block
Shows preview of any shortcode on editor side. It renders shortcode in the editor side so editor does not need to visit front side.
Blocks to Shortcode – Use blocks everywhere: in page templates, Elementor, etc.
blocks-to-shortcode
Easily convert blocks into shortcodes and reuse them anywhere on your site - in posts, pages, widgets, templates, and page builders like Elementor.
Uix Shortcodes
uix-shortcodes
Uix Shortcodes brings an amazing set of beautiful and useful elements to your site that lets you do nifty things with very little effort.
Simple Shortcode Block
simple-shortcode-block
A simple block to render a shortcode in a dynamic way into the new editor Gutenberg.
Shortcode Redirect Developer Profile
6 plugins · 32K total installs
How We Detect Shortcode Redirect
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
Please wait while you are redirected...or <a href=