Shortfundly Shortfundly Widget and Shortcode Security & Risk Analysis

wordpress.org/plugins/shortfundly

Provides both widgets and shortcodes to help you display top rated shortfilms on your website. The official Shortfundly shortfilm plugin.

0 active installs v1.0 PHP 7.0+ WP 3.0.1+ Updated Jan 5, 2018
shortcodeshortfilmsshortfundlyvideoswidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Shortfundly Shortfundly Widget and Shortcode Safe to Use in 2026?

Generally Safe

Score 85/100

Shortfundly Shortfundly Widget and Shortcode has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The shortfundly v1.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for SQL queries, having no recorded vulnerabilities, and performing nonces and capability checks on some entry points. The absence of dangerous functions, file operations, and raw SQL queries further contributes to a generally secure foundation.

However, there are significant areas of concern. The plugin exposes two AJAX handlers without any authentication checks, creating a substantial attack surface. Furthermore, a notable portion of its output (46%) is not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled carefully. The external HTTP request, while only one, also represents a potential vector for exploitation if the external service is compromised or the request is not handled securely.

While the vulnerability history is clean, suggesting good development hygiene thus far, the identified issues in the static analysis are pressing. The lack of authentication on AJAX endpoints is a critical oversight that could be exploited by unauthenticated users. The unescaped output, while not as severe as direct unauthenticated entry points, still presents a risk that requires immediate attention. Overall, the plugin has strengths in data handling but weaknesses in access control and output sanitization.

Key Concerns

  • Unprotected AJAX handlers
  • Significant portion of unescaped output
  • External HTTP request without context
Vulnerabilities
None known

Shortfundly Shortfundly Widget and Shortcode Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Shortfundly Shortfundly Widget and Shortcode Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Shortfundly Shortfundly Widget and Shortcode Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
12
14 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

54% escaped26 total outputs
Attack Surface
2 unprotected

Shortfundly Shortfundly Widget and Shortcode Attack Surface

Entry Points3
Unprotected2

AJAX Handlers 2

authwp_ajax_shortfundly_badges_refresh_profileshortfundly-plugin.php:166
authwp_ajax_shortfundly_badges_refresh_profil2shortfundly-plugin.php:191

Shortcodes 1

[shortfundly-plugin] shortfundly-plugin.php:273
WordPress Hooks 5
actionadmin_menushortfundly-plugin.php:38
actionwp_headshortfundly-plugin.php:202
actionwidgets_initshortfundly-plugin.php:252
actionadmin_headshortfundly-plugin.php:284
actionwp_enqueue_scriptsshortfundly-plugin.php:299
Maintenance & Trust

Shortfundly Shortfundly Widget and Shortcode Maintenance & Trust

Maintenance Signals

WordPress version tested4.0.38
Last updatedJan 5, 2018
PHP min version7.0
Downloads963

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Shortfundly Shortfundly Widget and Shortcode Developer Profile

shortfundly

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Shortfundly Shortfundly Widget and Shortcode

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/shortfundly-plugin/shortfundly-plugin-backend.css/wp-content/plugins/shortfundly-plugin/shortfundly-plugin-frontend.css

HTML / DOM Fingerprints

JS Globals
ajaxurl
FAQ

Frequently Asked Questions about Shortfundly Shortfundly Widget and Shortcode