
Shortcodes Finder Security & Risk Analysis
wordpress.org/plugins/shortcodes-finderShortcodes Finder helps you to find, test, clean and get informations about the shortcodes in your WordPress website posts, pages and custom contents.
Is Shortcodes Finder Safe to Use in 2026?
Generally Safe
Score 99/100Shortcodes Finder has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'shortcodes-finder' plugin v1.6.1 presents a concerning security posture primarily due to its unprotected attack surface. With 4 AJAX handlers identified and all of them lacking authentication checks, there's a significant risk of unauthorized actions being performed by unauthenticated users. This, combined with the absence of any capability checks, makes these entry points highly vulnerable.
The static analysis also highlights concerns regarding data sanitization. While the majority of output escaping appears to be handled correctly, one unsanitized path flow identified through taint analysis warrants attention, potentially leading to cross-site scripting vulnerabilities if not properly addressed. Furthermore, the presence of SQL queries that are not using prepared statements is a critical risk that could lead to SQL injection vulnerabilities.
Historically, the plugin has had two medium-severity vulnerabilities, both related to Cross-site Scripting. The fact that these are now patched is a positive sign, but the recurring nature of XSS vulnerabilities suggests potential ongoing challenges with input sanitization within the plugin's codebase. While the plugin has strengths in avoiding dangerous functions and external requests, the significant number of unprotected AJAX endpoints and the raw SQL queries pose the most immediate and severe risks.
Key Concerns
- AJAX handlers without auth checks
- SQL queries not using prepared statements
- Unsanitized path flow in taint analysis
- Medium severity XSS vulnerabilities in history
- Lack of capability checks on entry points
Shortcodes Finder Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Shortcodes Finder <= 1.5.4 - Reflected Cross-Site Scripting via nonce
Shortcodes Finder <= 1.5.3 - Reflected Cross-Site Scripting
Shortcodes Finder Release Timeline
Shortcodes Finder Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Shortcodes Finder Attack Surface
AJAX Handlers 4
WordPress Hooks 9
Maintenance & Trust
Shortcodes Finder Maintenance & Trust
Maintenance Signals
Community Trust
Shortcodes Finder Alternatives
Column Shortcodes
column-shortcodes
Adds shortcodes to easily create columns in your posts or pages.
YITH WooCommerce Ajax Search
yith-woocommerce-ajax-search
YITH WooCommerce Ajax Search allows your users to search products in real time.
Apollo13 Framework Extensions
apollo13-framework-extensions
Adds custom post types, shortcodes and some features that are used in themes built on Apollo13 Framework.
Futurio Extra
futurio-extra
Futurio Extra add extra features to Futurio theme like widgets, WooCommerce options, Elementor widgets, one click demo import and much more.
ND Shortcodes
nd-shortcodes
The plugin adds some useful components to your page builder ( Elementor or WP Bakery Page Builder ). All components are full responsive and retina rea …
Shortcodes Finder Developer Profile
3 plugins · 9K total installs
How We Detect Shortcodes Finder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shortcodes-finder/admin/css/shortcodes-finder-admin.css/wp-content/plugins/shortcodes-finder/admin/js/shortcodes-finder-admin.jsadmin/js/shortcodes-finder-admin.jsshortcodes-finder-admin.css?ver=shortcodes-finder-admin.js?ver=HTML / DOM Fingerprints
scribit_creditdata-postidajax_vars