
Shortcodely Security & Risk Analysis
wordpress.org/plugins/shortcodelyEnable the usage of shortcodes almost any where on your website
Is Shortcodely Safe to Use in 2026?
Generally Safe
Score 85/100Shortcodely has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The shortcodely plugin v1.0.1 exhibits a generally good security posture based on the provided static analysis. The plugin has a small attack surface consisting only of two shortcodes, and importantly, none of these entry points appear to be unprotected. The plugin also demonstrates strong practices regarding SQL queries, with 100% of them utilizing prepared statements. Furthermore, the presence of capability checks for both shortcodes indicates an effort to restrict access to potentially sensitive functionality.
However, a significant concern arises from the output escaping. With only 8% of the 12 total outputs properly escaped, this leaves a substantial portion vulnerable to Cross-Site Scripting (XSS) attacks. While there are no recorded vulnerabilities in its history, suggesting a clean track record, the lack of proper output escaping is a notable weakness that could be exploited. The absence of taint analysis flows could be due to the static analysis tool's limitations or a genuinely limited code structure, but the output escaping issue remains the primary actionable risk identified.
Key Concerns
- Low percentage of properly escaped output
Shortcodely Security Vulnerabilities
Shortcodely Code Analysis
Output Escaping
Shortcodely Attack Surface
Shortcodes 2
WordPress Hooks 9
Maintenance & Trust
Shortcodely Maintenance & Trust
Maintenance Signals
Community Trust
Shortcodely Alternatives
WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder
wdesignkit
3000+ Elementor Templates, Gutenberg Templates, Widgets Builder for Elementor, Gutenberg & Bricks, Cloud Workspace & Figma Files, 160+ Widgets Library
HT Mega Addons for Elementor – Elementor Widgets & Template Builder
ht-mega-for-elementor
Elementor addon offering 135+ widgets — Mega Menu, Ready Templates, Page Builder, Slider, Gallery, Post Grid, AI Writer & more.
Contact Form by BestWebSoft – Advanced WP Contact Form Builder for WordPress
contact-form-plugin
The most powerful and user-friendly WordPress contact form plugin. Create beautiful contact forms, widgets and pages using shortcodes.
Apollo13 Framework Extensions
apollo13-framework-extensions
Adds custom post types, shortcodes and some features that are used in themes built on Apollo13 Framework.
Disable Author Pages
disable-author-pages
Disable the author pages
Shortcodely Developer Profile
2 plugins · 1K total installs
How We Detect Shortcodely
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shortcodely/shortcodely.css/wp-content/plugins/shortcodely/shortcodely.js/wp-content/plugins/shortcodely/shortcodely.jsshortcodely/shortcodely.css?ver=shortcodely/shortcodely.js?ver=HTML / DOM Fingerprints
shortcodely-widget-areashortcodely_widgetdata-widget-areadata-widget-id[do_widget id=[do_widget][do_widget_area]