
A Shortcode Tester Security & Risk Analysis
wordpress.org/plugins/shortcode-testerThe Shortcode Tester is a post editor tool for WordPress developers that displays in a popup window the HTML generated by WordPress shortcodes, i.e.
Is A Shortcode Tester Safe to Use in 2026?
Generally Safe
Score 85/100A Shortcode Tester has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "shortcode-tester" plugin, version 1.2.2, exhibits a strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface, with zero identified entry points. The code signals also indicate good practices, with 100% of SQL queries using prepared statements and a nonce check present. There are no critical or high severity taint flows detected, and the plugin has no recorded vulnerability history. This suggests a well-developed and secure plugin in its current state. However, a significant concern arises from the lack of output escaping, with 0% of the 3 identified outputs being properly escaped. This presents a potential Cross-Site Scripting (XSS) vulnerability if user-controlled data is ever introduced into these output contexts, even with the limited attack surface. Furthermore, the absence of capability checks for the single nonce check means that any authenticated user, regardless of their role, could potentially trigger the functionality secured by the nonce. While the current data indicates no known vulnerabilities, the output escaping deficiency is a notable weakness that should be addressed.
Key Concerns
- No proper output escaping
- Nonce check without capability check
A Shortcode Tester Security Vulnerabilities
A Shortcode Tester Code Analysis
Output Escaping
Data Flow Analysis
A Shortcode Tester Attack Surface
WordPress Hooks 18
Maintenance & Trust
A Shortcode Tester Maintenance & Trust
Maintenance Signals
Community Trust
A Shortcode Tester Alternatives
JSM Show Registered Shortcodes
jsm-show-registered-shortcodes
Simple and lightweight plugin to show all registered shortcodes under a "Registered Shortcodes" toolbar menu item.
Flipbox Addon for WPBakery Page Builder (formerly Visual Composer)
vc-flipbox
Checkout our Latest WordPress Themes - 100% Free
Clean unused shortcodes
clean-unused-shortcodes
Remove unused shortcodes from your posts content with an improved user interface and advanced functionality.
Tipso
tipso
Tipso is a simple Wordpress tooltip plugin.
Shortcodes In Use
shortcodes-in-use
List all the shortcodes that you have used within your content or custom fields, and find out exactly where they have been used.
A Shortcode Tester Developer Profile
4 plugins · 40 total installs
How We Detect A Shortcode Tester
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shortcode-tester/css/mf2tk_macros_admin.css/wp-content/plugins/shortcode-tester/js/mf2tk_macros_admin.js/wp-content/plugins/shortcode-tester/js/mf2tk_macros_admin.jsshortcode-tester/css/mf2tk_macros_admin.css?ver=shortcode-tester/js/mf2tk_macros_admin.js?ver=HTML / DOM Fingerprints
sct_ix-popupsct_ix-headingsct_ix-instructions<!-- ##### ACTION:wp_body_open --><!-- ##### FILTER:the_content start --><!-- ##### FILTER:the_content end --><!-- ##### ACTION:loop_end -->+3 moreid="sct_ix-shortcode-tester"id="sct_ix-popup_margin"id="mf2tk-shortcode-tester"id="button-mf2tk-shortcode-tester-close"data-noncemf2tk_macros_admin