
Shortfundly Shortfundly Widget and Shortcode Security & Risk Analysis
wordpress.org/plugins/shortfundlyProvides both widgets and shortcodes to help you display top rated shortfilms on your website. The official Shortfundly shortfilm plugin.
Is Shortfundly Shortfundly Widget and Shortcode Safe to Use in 2026?
Generally Safe
Score 85/100Shortfundly Shortfundly Widget and Shortcode has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The shortfundly v1.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for SQL queries, having no recorded vulnerabilities, and performing nonces and capability checks on some entry points. The absence of dangerous functions, file operations, and raw SQL queries further contributes to a generally secure foundation.
However, there are significant areas of concern. The plugin exposes two AJAX handlers without any authentication checks, creating a substantial attack surface. Furthermore, a notable portion of its output (46%) is not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled carefully. The external HTTP request, while only one, also represents a potential vector for exploitation if the external service is compromised or the request is not handled securely.
While the vulnerability history is clean, suggesting good development hygiene thus far, the identified issues in the static analysis are pressing. The lack of authentication on AJAX endpoints is a critical oversight that could be exploited by unauthenticated users. The unescaped output, while not as severe as direct unauthenticated entry points, still presents a risk that requires immediate attention. Overall, the plugin has strengths in data handling but weaknesses in access control and output sanitization.
Key Concerns
- Unprotected AJAX handlers
- Significant portion of unescaped output
- External HTTP request without context
Shortfundly Shortfundly Widget and Shortcode Security Vulnerabilities
Shortfundly Shortfundly Widget and Shortcode Release Timeline
Shortfundly Shortfundly Widget and Shortcode Code Analysis
Output Escaping
Shortfundly Shortfundly Widget and Shortcode Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
Shortfundly Shortfundly Widget and Shortcode Maintenance & Trust
Maintenance Signals
Community Trust
Shortfundly Shortfundly Widget and Shortcode Alternatives
Auto Last Youtube Video
auto-last-youtube-video
This plugin provides both Widget and Shortcode to show latest videos from any public Youtube channel.
Feeds for TikTok (TikTok feed, video, and gallery plugin)
feeds-for-tiktok
The best way to display TikTok videos on your WordPress website. Display clean, customizable, and responsive TikTok feeds from your TikTok account.
Contact Form by BestWebSoft – Advanced WP Contact Form Builder for WordPress
contact-form-plugin
The most powerful and user-friendly WordPress contact form plugin. Create beautiful contact forms, widgets and pages using shortcodes.
Apollo13 Framework Extensions
apollo13-framework-extensions
Adds custom post types, shortcodes and some features that are used in themes built on Apollo13 Framework.
Kaya QR Code Generator
kaya-qr-code-generator
Generate QR Code through Widgets and Shortcodes, without any dependencies.
Shortfundly Shortfundly Widget and Shortcode Developer Profile
1 plugin · 0 total installs
How We Detect Shortfundly Shortfundly Widget and Shortcode
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shortfundly-plugin/shortfundly-plugin-backend.css/wp-content/plugins/shortfundly-plugin/shortfundly-plugin-frontend.cssHTML / DOM Fingerprints
ajaxurl