
Show/Hide Shortcode Security & Risk Analysis
wordpress.org/plugins/showhide-shortcodeSmall and efficient plugin implementing dynamic "Show more..." links. Just use the [showhide] shortcode, there is no addition to the backend.
Is Show/Hide Shortcode Safe to Use in 2026?
Generally Safe
Score 91/100Show/Hide Shortcode has a strong security track record. Known vulnerabilities have been patched promptly.
The 'showhide-shortcode' plugin v1.0.1 exhibits a generally good security posture in its static analysis, with no detected dangerous functions, all SQL queries using prepared statements, and all output properly escaped. The attack surface is minimal, consisting of a single shortcode, and importantly, there are no unprotected entry points found in the static analysis, which is a significant strength. The absence of any taint analysis findings further suggests that readily exploitable vulnerabilities within the code itself are unlikely at this version. However, the plugin's vulnerability history is a major concern. It has a known CVE with a history of Cross-Site Scripting (XSS) vulnerabilities. Although there are no currently unpatched CVEs, the past occurrence of a medium-severity XSS vulnerability, especially one that has been fixed, indicates a tendency for such issues to arise. This suggests that while the current version might be clean, careful monitoring and prompt updates are essential, as future versions could potentially reintroduce similar flaws if not rigorously tested.
Key Concerns
- Known medium severity XSS vulnerability in history
- No nonce checks on shortcode entry point
- No capability checks on shortcode entry point
Show/Hide Shortcode Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Show/Hide Shortcode <= 1.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Show/Hide Shortcode Code Analysis
Output Escaping
Show/Hide Shortcode Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
Show/Hide Shortcode Maintenance & Trust
Maintenance Signals
Community Trust
Show/Hide Shortcode Alternatives
FR Read More
fr-read-more
Create expandable content sections on WordPress. Let visitors reveal hidden content with a click.
Webspero Read More Toggle
webspero-read-more-toggle
Adds a simple "Read More / Read Less" toggle to long content using lightweight JavaScript. Ideal for blogs, FAQs, or excerpts.
Read More WP
read-more-wp
Create excerpts and hide text with an elegant toggle button to show more.
Read More Buddy
read-more-buddy
A simple and light but highly customizable to hide predefined text, through use of a shortcode and add a 'Read More' button.
KM-ShowHide
km-showhide
This simple plugin allows you to toggle your content inside shortcode.
Show/Hide Shortcode Developer Profile
1 plugin · 300 total installs
How We Detect Show/Hide Shortcode
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/showhide-shortcode/script.js/wp-content/plugins/showhide-shortcode/script.jsshowhide-shortcode/script.js?ver=HTML / DOM Fingerprints
showhideshortcode-contentdata-show-captiondata-hide-caption<div class="showhideshortcode-content"><p><a href="#" data-show-caption=""></a></p><div style="display: none;">