
Show All Posts Shortcode Security & Risk Analysis
wordpress.org/plugins/show-aposts-shortcodeProvides a [show-aposts] shortcode for displaying posts or pages within a post or page using the get_posts() function.
Is Show All Posts Shortcode Safe to Use in 2026?
Generally Safe
Score 85/100Show All Posts Shortcode has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "show-aposts-shortcode" v1.0 plugin exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, SQL queries without prepared statements, unescaped output, file operations, and external HTTP requests are all positive indicators. Furthermore, the plugin has no recorded vulnerability history, including no known CVEs. The minimal attack surface, consisting of only one shortcode with no apparent authentication checks, is also a strength.
However, the complete lack of nonce and capability checks across all entry points, particularly for the shortcode, represents a significant concern. While the static analysis did not identify any direct taint flows or immediate risks, this absence of authorization checks leaves the shortcode vulnerable to potential manipulation if its functionality can be exploited in conjunction with other WordPress features or user actions. The plugin's lack of a vulnerability history is positive but doesn't entirely mitigate the risk posed by missing security controls.
In conclusion, the plugin demonstrates good coding practices in several areas, such as prepared SQL statements and output escaping. However, the critical oversight of omitting nonce and capability checks on its sole entry point is a weakness that could lead to security issues. Users should proceed with caution until this authorization gap is addressed.
Key Concerns
- Missing nonce/capability checks on shortcode
Show All Posts Shortcode Security Vulnerabilities
Show All Posts Shortcode Code Analysis
Show All Posts Shortcode Attack Surface
Shortcodes 1
Maintenance & Trust
Show All Posts Shortcode Maintenance & Trust
Maintenance Signals
Community Trust
Show All Posts Shortcode Alternatives
Show Menu Shortcode
show-menu-shortcode
Provides a [show-menu] shortcode for displaying a menu within a post or page.
Popular Brand Icons – Simple Icons
simple-icons
An easy to use lightweight SVG icons plugin with over 1500+ brand icons. Use these icons in your menus, widgets, posts, or pages.
BuddyMenu BuddyLinks
buddymenu-buddylinks
BuddyPress BuddyLinks does three things really well:
Easy menus
jquery-easy-menu
Plugin to load different types of menus with pictures.
DCO Shortcodes Menu
dco-shortcodes-menu
Allow you to add shortcodes menu to the editor
Show All Posts Shortcode Developer Profile
2 plugins · 420 total installs
How We Detect Show All Posts Shortcode
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
show-aposts<div class="show-aposts"><ul><li><a href =