
Snippet Shortcodes Security & Risk Analysis
wordpress.org/plugins/shortcode-variablesCreate a library of custom shortcodes and reusable content, and seamlessly insert them into your posts and pages.
Is Snippet Shortcodes Safe to Use in 2026?
Generally Safe
Score 99/100Snippet Shortcodes has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "shortcode-variables" plugin version 5.1.2 exhibits a mixed security posture. While the plugin demonstrates good practices by having all identified entry points (AJAX handlers, REST API routes, shortcodes) protected by some form of authentication or capability check, and a high percentage of SQL queries utilizing prepared statements, several areas raise concerns. The output escaping is a significant weakness, with less than half of the outputs being properly sanitized, potentially exposing the site to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is involved in these outputs.
The taint analysis, while not revealing critical or high-severity issues, did identify three flows with unsanitized paths. Combined with the historically known vulnerabilities, particularly medium-severity ones related to Missing Authorization and CSRF, this suggests a recurring pattern of subtle security oversights. The presence of external HTTP requests also warrants careful monitoring, although their context and security are not detailed here.
In conclusion, the plugin has strengths in its foundational security measures like prepared statements and auth checks on entry points. However, the poor output escaping and the history of authorization and CSRF vulnerabilities, alongside the taint analysis findings, indicate that ongoing vigilance and potential future patching are necessary to maintain a secure environment.
Key Concerns
- Low output escaping percentage
- Taint flows with unsanitized paths
- History of medium severity CVEs
Snippet Shortcodes Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Snippet Shortcodes <= 4.1.6 - Authenticated (Subscriber+) Shortcode Deletion
Snippet Shortcodes <= 4.1.4 - Cross-Site Request Forgery
Snippet Shortcodes Release Timeline
Snippet Shortcodes Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Snippet Shortcodes Attack Surface
AJAX Handlers 6
Shortcodes 10
WordPress Hooks 13
Maintenance & Trust
Snippet Shortcodes Maintenance & Trust
Maintenance Signals
Community Trust
Snippet Shortcodes Alternatives
Post Snippets – Custom WordPress Code Snippets Customizer
post-snippets
Create WordPress custom snippets shortcodes and reusable content and insert them in into your posts and pages.
Custom Global Variables
custom-global-variables
Easily create custom variables that can be accessed globally in Wordpress and PHP. Retrieval of information is extremely fast, with no database calls.
Shortcoder — Create Shortcodes for Anything
shortcoder
Create custom "Shortcodes" easily for HTML, JavaScript, CSS code snippets and use the shortcodes within posts, pages & widgets
Woody Code Snippets – Insert PHP, CSS, JS, and Header/Footer Scripts
insert-php
Insert PHP, JavaScript, CSS, HTML, ads, and tracking code into WordPress headers, footers, pages, and content using conditional logic, without editing …
Shortcode in Menus
shortcode-in-menus
Allows you to add shortcodes in WordPress Navigation Menus.
Snippet Shortcodes Developer Profile
1 plugin · 4K total installs
How We Detect Snippet Shortcodes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shortcode-variables/assets/css/sh-cd-dashicon.css/wp-content/plugins/shortcode-variables/assets/js/marketing.js/wp-content/plugins/shortcode-variables/assets/zerbratooltips/zebra_tooltips.min.js/wp-content/plugins/shortcode-variables/assets/zerbratooltips/zebra_tooltips.min.css/wp-content/plugins/shortcode-variables/assets/css/sh-cd.css/wp-content/plugins/shortcode-variables/assets/fontawesome/css/fontawesome.min.css/wp-content/plugins/shortcode-variables/assets/fontawesome/css/solid.min.css/wp-content/plugins/shortcode-variables/assets/fontawesome/css/regular.min.css+3 more/wp-content/plugins/shortcode-variables/assets/js/marketing.js/wp-content/plugins/shortcode-variables/assets/zerbratooltips/zebra_tooltips.min.js/wp-content/plugins/shortcode-variables/assets/js/clipboard.min.js/wp-content/plugins/shortcode-variables/assets/js/sh-cd.jssh-cd-dashicon?ver=sh-cd-marketing?ver=zebra_tooltips.min.js?ver=zebra_tooltips.min.css?ver=sh-cd.css?ver=fontawesome.min.css?ver=solid.min.css?ver=regular.min.css?ver=brands.min.css?ver=clipboard.min.js?ver=sh-cd.js?ver=HTML / DOM Fingerprints
sh-cd-admin-notice-wrappersh_cd