
SimTerm Security & Risk Analysis
wordpress.org/plugins/simtermMake demos of your terminal commands and output in an attractive way.
Is SimTerm Safe to Use in 2026?
Generally Safe
Score 85/100SimTerm has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The security posture of simterm v0.3.0 appears to be a mixed bag, exhibiting some good practices alongside significant concerns. On the positive side, the plugin demonstrates excellent security by not using any dangerous functions, file operations, external HTTP requests, or bundled libraries. It also correctly utilizes prepared statements for all SQL queries and has no known vulnerabilities or CVEs. However, the code analysis reveals critical weaknesses in output escaping. A concerning 0% of the 33 identified outputs are properly escaped, suggesting a high likelihood of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the lack of nonce and capability checks across all entry points, including its sole shortcode, creates a significant attack surface that is entirely unprotected against unauthorized actions or malicious input injection.
Key Concerns
- 0% of outputs properly escaped
- 0 Nonce checks on entry points
- 0 Capability checks on entry points
SimTerm Security Vulnerabilities
SimTerm Code Analysis
Output Escaping
SimTerm Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
SimTerm Maintenance & Trust
Maintenance Signals
Community Trust
SimTerm Alternatives
WPTerm
wpterm
An xterm-like plugin to run non-interactive shell commands.
WP Composer
composer
Adding Composer dependency management to WP CLI.
WP-ShkShell
wp-shkshell
WP-ShkShell provides a terminal-like box for embedding terminal commands within pages or posts. It also support multi-lines, multi-commands and has s …
WooCommerce
woocommerce
Everything you need to launch an online store in days and keep it growing for years. From your first sale to millions in revenue, Woo is with you.
Inline Related Posts
intelly-related-posts
Inline Related Posts AUTOMATICALLY inserts related posts INSIDE your content, capturing immediately the reader's attention.
SimTerm Developer Profile
1 plugin · 40 total installs
How We Detect SimTerm
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/simterm/css/show-your-terms.min.css/wp-content/plugins/simterm/css/simterm.css/wp-content/plugins/simterm/js/simterm.js/wp-content/plugins/simterm/js/show-your-terms.min.js/wp-content/plugins/simterm/js/show-your-terms.min.js/wp-content/plugins/simterm/js/simterm.jssimterm-showyourtermssimterm-launchersimterm-showyourtermscsssimterm-extracssHTML / DOM Fingerprints
show-your-termssyt-windowsyt-contentsyt-commandsyt-usersyt-cursorsyt-plain-outputsyt-animated-outputdata-animateddata-titledata-statusbardata-themewindow.showYourTermswindow.SimTermLauncherSimTermView::render('live/syt', array('data' => $data))