
Shortcode Reference Security & Risk Analysis
wordpress.org/plugins/shortcode-referenceThis plugin will provide a list and details about available shortcodes in your current installment. All when you need it most - when editing content.
Is Shortcode Reference Safe to Use in 2026?
Generally Safe
Score 85/100Shortcode Reference has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "shortcode-reference" plugin version 1.0.0 presents a mixed security posture. On the positive side, the plugin demonstrates good practices regarding SQL queries, ensuring they are all prepared, and outputs are properly escaped. There are no dangerous functions, file operations, external HTTP requests, or bundled libraries identified, which are all favorable signs. Furthermore, the plugin has no recorded vulnerability history, suggesting a stable and potentially secure development track record.
However, a significant concern arises from the attack surface analysis. The plugin exposes one AJAX handler that lacks any authentication or capability checks. This unprotected entry point represents a direct risk, as any unauthenticated user could potentially trigger this handler. While the taint analysis shows no identified flows, the presence of an unprotected AJAX endpoint means that malicious input could theoretically be processed without proper validation or authorization, leading to unintended actions or information disclosure. The absence of nonce checks on this AJAX handler further exacerbates this risk.
In conclusion, while the plugin exhibits strengths in its handling of data and its clean vulnerability history, the single unprotected AJAX handler is a critical weakness that requires immediate attention. The lack of authentication and nonce checks on this entry point significantly increases the plugin's vulnerability to exploitation. The overall risk is moderate due to this specific, but impactful, oversight.
Key Concerns
- AJAX handler without auth checks
- AJAX handler without nonce checks
Shortcode Reference Security Vulnerabilities
Shortcode Reference Code Analysis
Shortcode Reference Attack Surface
AJAX Handlers 1
WordPress Hooks 3
Maintenance & Trust
Shortcode Reference Maintenance & Trust
Maintenance Signals
Community Trust
Shortcode Reference Alternatives
Display Posts – Easy lists, grids, navigation, and more
display-posts-shortcode
Add a listing of content on your website using a simple shortcode. Filter the results by category, author, and more.
Apollo13 Framework Extensions
apollo13-framework-extensions
Adds custom post types, shortcodes and some features that are used in themes built on Apollo13 Framework.
Posts in Page
posts-in-page
Easily add one or more posts to any page using simple shortcodes.
Disable Author Pages
disable-author-pages
Disable the author pages
Admin Collapse Subpages
admin-collapse-subpages
Using this plugin one can easily collapse/expand pages with children and grand children.
Shortcode Reference Developer Profile
1 plugin · 100 total installs
How We Detect Shortcode Reference
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shortcode-reference/css/shortcode-reference.css/wp-content/plugins/shortcode-reference/js/shortcode-reference.js/wp-content/plugins/shortcode-reference/js/shortcode-reference.jsshortcode-reference-style?ver=shortcode-reference-js?ver=HTML / DOM Fingerprints
/wp-json/shortcode-reference/v1/find