
SoundCloud Shortcode Security & Risk Analysis
wordpress.org/plugins/soundcloud-shortcodeSoundCloud Shortcode plugin for WordPress
Is SoundCloud Shortcode Safe to Use in 2026?
Mostly Safe
Score 84/100SoundCloud Shortcode is generally safe to use though it hasn't been updated recently. 2 past CVEs were resolved. Keep it updated.
The soundcloud-shortcode plugin v4.0.3 exhibits a generally good security posture based on the static analysis. The absence of dangerous functions, file operations, external HTTP requests, and the consistent use of prepared statements for SQL queries are positive indicators. All identified outputs are properly escaped, and the presence of a capability check on the single shortcode entry point is a good practice.
However, the static analysis reveals a significant concern: the lack of nonce checks on the sole entry point, the shortcode. While there are no reported flows with unsanitized paths or critical taint issues, the absence of nonce checks opens the door to potential Cross-Site Request Forgery (CSRF) attacks if the shortcode's functionality can be triggered in a way that impacts user security or data. The vulnerability history also indicates a past pattern of Cross-Site Scripting vulnerabilities, which, while currently unpatched, suggests that careful input sanitization and output escaping are crucial for this plugin.
In conclusion, while the plugin has strong internal coding practices for data handling and output, the missing nonce check represents a tangible security weakness. Coupled with the historical prevalence of XSS, diligent monitoring for new vulnerabilities and addressing any identified weaknesses, particularly around input handling, is recommended. The plugin's small attack surface is a mitigating factor, but the identified potential for CSRF should not be overlooked.
Key Concerns
- Missing nonce check on shortcode entry point
- Historical XSS vulnerabilities
SoundCloud Shortcode Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
SoundCloud Shortcode <= 4.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode
SoundCloud Shortcode <= 3.1.0 - Authenticated (Administrator+) Stored Cross-Site Scripting
SoundCloud Shortcode Code Analysis
Output Escaping
SoundCloud Shortcode Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
SoundCloud Shortcode Maintenance & Trust
Maintenance Signals
Community Trust
SoundCloud Shortcode Alternatives
WP Shortcodes Plugin — Shortcodes Ultimate
shortcodes-ultimate
A comprehensive collection of visual components for your site
MW WP Form
mw-wp-form
MW WP Form is shortcode base contact form plugin. This plugin have many features. For example you can use many validation rules, inquiry data saving, …
Shortcoder — Create Shortcodes for Anything
shortcoder
Create custom "Shortcodes" easily for HTML, JavaScript, CSS code snippets and use the shortcodes within posts, pages & widgets
Display Posts – Easy lists, grids, navigation, and more
display-posts-shortcode
Add a listing of content on your website using a simple shortcode. Filter the results by category, author, and more.
WP Show Posts
wp-show-posts
Add posts to your website from any post type using a simple shortcode.
SoundCloud Shortcode Developer Profile
4 plugins · 5K total installs
How We Detect SoundCloud Shortcode
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
<iframesoundcloud.com/tracks/soundcloud.com/sets/soundcloud.com/users/