
EZ SHORTCURL Shortcodes to Fetch and Parse External Content Security & Risk Analysis
wordpress.org/plugins/shortcurlUse the shortcodes remote_get and preg_replace to fetch external content and parse it to use on your page or post.
Is EZ SHORTCURL Shortcodes to Fetch and Parse External Content Safe to Use in 2026?
Generally Safe
Score 85/100EZ SHORTCURL Shortcodes to Fetch and Parse External Content has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The shortcurl plugin v3.17.49 presents a mixed security posture. While the static analysis indicates a clean slate regarding SQL injection and taint analysis, with all SQL queries using prepared statements and no critical or high severity taint flows detected, there are several concerning signals. The plugin exhibits a lack of authorization checks, with zero nonce checks and zero capability checks across all identified entry points, including shortcodes, AJAX handlers, and REST API routes. This absence of proper authentication and authorization mechanisms creates a significant risk for unauthorized actions if any of the entry points are exploitable. Furthermore, the presence of the `create_function` dangerous function is a known security risk that can lead to code execution vulnerabilities if not handled with extreme care. The output escaping is also only partially implemented, with over half of the outputs not properly escaped, potentially leading to cross-site scripting (XSS) vulnerabilities.
The plugin's vulnerability history is a significant positive factor, showing no previously recorded CVEs. This suggests a generally well-maintained codebase or limited exposure to advanced security testing. However, the absence of past vulnerabilities should not overshadow the current identified risks. The combination of a large attack surface with zero authorization checks and the presence of dangerous functions outweighs the clean CVE history. The plugin is therefore considered to have a moderate to high risk profile due to the potential for exploitation of its unprotected entry points and the use of insecure coding practices, despite the lack of historical vulnerabilities.
Key Concerns
- Missing nonce checks on entry points
- Missing capability checks on entry points
- Presence of dangerous function 'create_function'
- Low percentage of properly escaped output
EZ SHORTCURL Shortcodes to Fetch and Parse External Content Security Vulnerabilities
EZ SHORTCURL Shortcodes to Fetch and Parse External Content Code Analysis
Dangerous Functions Found
Output Escaping
EZ SHORTCURL Shortcodes to Fetch and Parse External Content Attack Surface
Shortcodes 4
WordPress Hooks 3
Maintenance & Trust
EZ SHORTCURL Shortcodes to Fetch and Parse External Content Maintenance & Trust
Maintenance Signals
Community Trust
EZ SHORTCURL Shortcodes to Fetch and Parse External Content Alternatives
Fetch URL – Fetch and Parse External Content
fetchurl
Use the remote_get and preg_replace shortcodes to fetch external content and parse it to use on your page or post.
WP Shortcodes Plugin — Shortcodes Ultimate
shortcodes-ultimate
A comprehensive collection of visual components for your site
MW WP Form
mw-wp-form
MW WP Form is shortcode base contact form plugin. This plugin have many features. For example you can use many validation rules, inquiry data saving, …
Shortcoder — Create Shortcodes for Anything
shortcoder
Create custom "Shortcodes" easily for HTML, JavaScript, CSS code snippets and use the shortcodes within posts, pages & widgets
Razorpay for WooCommerce
woo-razorpay
Start accepting payments in minutes with 100% digital onboarding & feature filled Razorpay payment gateway with the WooCommerce plugin.
EZ SHORTCURL Shortcodes to Fetch and Parse External Content Developer Profile
9 plugins · 101K total installs
How We Detect EZ SHORTCURL Shortcodes to Fetch and Parse External Content
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
SHORTCURL Main Plugin File @package SHORTCURL Copyright © 2012-2017 Eli Scheetz (email: wordpress@ieonly.com) This program is free software; you can redistribute it+8 more[remote_get][preg_replace][preg_replace_shortcode][str_replace]