
Shortcodes Analyzer Security & Risk Analysis
wordpress.org/plugins/shortcodes-analyzerScan your entire WordPress site in one click to find exactly where every shortcode is used across posts, pages, and custom post types.
Is Shortcodes Analyzer Safe to Use in 2026?
Generally Safe
Score 100/100Shortcodes Analyzer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'shortcodes-analyzer' plugin v1.0.1 exhibits a generally strong security posture based on the provided static analysis. It demonstrates good practices by utilizing prepared statements for all SQL queries and performing nonce checks on its AJAX endpoints. Furthermore, the absence of known CVEs and a clean vulnerability history suggest a well-maintained and secure codebase.
However, there are areas of concern. The taint analysis reveals two flows with unsanitized paths, flagged as high severity. While the total attack surface is small, and all entry points have some form of protection, these unsanitized paths represent a potential risk if user-supplied data is involved in file operations or sensitive logic without proper sanitization. The static analysis also indicates that 18% of outputs are not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if sensitive data is displayed without adequate sanitization.
In conclusion, while the plugin has a solid foundation with secure database interactions and input validation for its AJAX handlers, the identified high-severity taint flows and the proportion of unescaped outputs warrant attention. Addressing these specific issues will further solidify the plugin's security and mitigate potential risks.
Key Concerns
- High severity taint flows with unsanitized paths
- Significant percentage of unescaped outputs
Shortcodes Analyzer Security Vulnerabilities
Shortcodes Analyzer Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Shortcodes Analyzer Attack Surface
AJAX Handlers 2
WordPress Hooks 2
Maintenance & Trust
Shortcodes Analyzer Maintenance & Trust
Maintenance Signals
Community Trust
Shortcodes Analyzer Alternatives
Shortcode Search | WordPress Search Bar Shortcode Plugin
shortcode-search
Shortcode Search is a simple plugin that lets users add a search bar anywhere on their WordPress website using the shortcode [search].
CF7 Shortcode Finder
cf7-shortcode-finder
This plugin is compatible with Contact form 7 and it will help you to locate which form is placed on which page. This will be helpful in tracking down …
Remove Empty Shortcodes
remove-empty-shortcodes
Automatically removes empty or inactive shortcodes from your content while preserving your original database entries.
WP Shortcodes Plugin — Shortcodes Ultimate
shortcodes-ultimate
A comprehensive collection of visual components for your site
MW WP Form
mw-wp-form
MW WP Form is shortcode base contact form plugin. This plugin have many features. For example you can use many validation rules, inquiry data saving, …
Shortcodes Analyzer Developer Profile
6 plugins · 1K total installs
How We Detect Shortcodes Analyzer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shortcodes-analyzer/assets/css/styles.css/wp-content/plugins/shortcodes-analyzer/assets/js/scripts.js/wp-content/plugins/shortcodes-analyzer/assets/js/scripts.jsshortcodes-analyzer/assets/css/styles.css?ver=shortcodes-analyzer/assets/js/scripts.js?ver=HTML / DOM Fingerprints
admin_ajax