
Shortcodes In Use Security & Risk Analysis
wordpress.org/plugins/shortcodes-in-useList all the shortcodes that you have used within your content or custom fields, and find out exactly where they have been used.
Is Shortcodes In Use Safe to Use in 2026?
Generally Safe
Score 85/100Shortcodes In Use has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "shortcodes-in-use" plugin v1.2.1 presents a generally good security posture based on the provided static analysis and vulnerability history. The plugin demonstrates strong adherence to secure coding practices by utilizing prepared statements for all SQL queries and implementing capability checks and nonce checks for its single shortcode entry point. The absence of external HTTP requests, file operations, and dangerous functions further strengthens its security. The fact that there are no recorded vulnerabilities, past or present, is a significant positive indicator of the developer's attention to security.
However, a key area for concern lies in the output escaping. With 42% of outputs properly escaped, there is a significant portion (58%) that remains unescaped. This could potentially lead to cross-site scripting (XSS) vulnerabilities if user-supplied data or dynamic content is directly rendered without proper sanitization. While the taint analysis did not reveal any immediate critical or high-severity flows, the lack of comprehensive output escaping represents the most significant identifiable risk in this plugin's current version. Overall, the plugin is well-developed from a security perspective regarding data handling and access control, but a critical review and remediation of unescaped outputs are recommended.
Key Concerns
- Low percentage of properly escaped outputs
Shortcodes In Use Security Vulnerabilities
Shortcodes In Use Code Analysis
SQL Query Safety
Output Escaping
Shortcodes In Use Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
Shortcodes In Use Maintenance & Trust
Maintenance Signals
Community Trust
Shortcodes In Use Alternatives
Clean unused shortcodes
clean-unused-shortcodes
Remove unused shortcodes from your posts content with an improved user interface and advanced functionality.
Hide Admin Bar Based on User Roles
hide-admin-bar-based-on-user-roles
Hide the WordPress Admin Bar for specific user roles, capabilities, devices, pages, or time windows. The ultimate toolbar control plugin for membershi …
Hide Admin Bar from Non-Admins
hide-admin-bar-from-non-admins
Hides the WordPress toolbar (admin bar) for all non-admin users. Simple plugin with no settings to configure.
WPS Bidouille
wps-bidouille
WPS Bidouille provides information about your WordPress and contains optimization tools.
Hide Admin Toolbar
hide-admin-toolbar
This plugin is used to hide admin toolbar from website. It will hide that bar when you are logged in and viewing the site.
Shortcodes In Use Developer Profile
3 plugins · 3K total installs
How We Detect Shortcodes In Use
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shortcodes-in-use/css/style.css/wp-content/plugins/shortcodes-in-use/js/shortcodes-in-use.jsshortcodes-in-use/css/style.css?ver=shortcodes-in-use/js/shortcodes-in-use.js?ver=HTML / DOM Fingerprints
s-i-u_redshortcodes-in-use-results-tables-i-u-admin-pageshortcodes_in_use_obj