Suffusion Shortcodes Security & Risk Analysis

wordpress.org/plugins/suffusion-shortcodes

The Suffusion theme used to be armed with a bunch of shortcodes prior to version 4.4.8.

200 active installs v1.05 PHP + WP + Updated Feb 22, 2016
shortcodessuffusion
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Suffusion Shortcodes Safe to Use in 2026?

Generally Safe

Score 85/100

Suffusion Shortcodes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The "suffusion-shortcodes" plugin v1.05 exhibits a mixed security posture. While the absence of known CVEs and a clean taint analysis are positive indicators, several code analysis findings raise concerns. The fact that 50% of output is not properly escaped presents a significant risk of Cross-Site Scripting (XSS) vulnerabilities, especially given the 16 shortcodes that can serve as entry points for user-supplied data. Furthermore, the complete lack of nonce checks and capability checks across all identified entry points, including shortcodes, means that any user, regardless of their role or authentication status, could potentially trigger shortcode functionality. This lack of authorization and validation is a major weakness.

Key Concerns

  • 50% of output unescaped
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

Suffusion Shortcodes Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Suffusion Shortcodes Release Timeline

v1.05Current
v1.04
v1.03
v1.02
v1.01
v1.00
Code Analysis
Analyzed Mar 16, 2026

Suffusion Shortcodes Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
6 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

50% escaped12 total outputs
Attack Surface

Suffusion Shortcodes Attack Surface

Entry Points16
Unprotected0

Shortcodes 16

[suffusion-categories] suffusion-shortcodes.php:30
[suffusion-the-year] suffusion-shortcodes.php:31
[suffusion-site-link] suffusion-shortcodes.php:32
[suffusion-the-author] suffusion-shortcodes.php:33
[suffusion-the-post] suffusion-shortcodes.php:34
[suffusion-login-url] suffusion-shortcodes.php:35
[suffusion-logout-url] suffusion-shortcodes.php:36
[suffusion-loginout] suffusion-shortcodes.php:37
[suffusion-register] suffusion-shortcodes.php:38
[suffusion-adsense] suffusion-shortcodes.php:39
[suffusion-tag-cloud] suffusion-shortcodes.php:40
[suffusion-widgets] suffusion-shortcodes.php:41
[suffusion-multic] suffusion-shortcodes.php:42
[suffusion-column] suffusion-shortcodes.php:43
[suffusion-flickr] suffusion-shortcodes.php:44
[audio] suffusion-shortcodes.php:86
WordPress Hooks 6
actionadmin_menusuffusion-integration-pack.php:17
actionadmin_enqueue_scriptssuffusion-integration-pack.php:18
actionwp_enqueue_scriptssuffusion-integration-pack.php:19
actionwp_print_scriptssuffusion-integration-pack.php:20
actionadmin_initsuffusion-shortcodes.php:28
actioninitsuffusion-shortcodes.php:597
Maintenance & Trust

Suffusion Shortcodes Maintenance & Trust

Maintenance Signals

WordPress version tested4.4.34
Last updatedFeb 22, 2016
PHP min version
Downloads15K

Community Trust

Rating100/100
Number of ratings6
Active installs200
Developer Profile

Suffusion Shortcodes Developer Profile

Sayontan Sinha

5 plugins · 10K total installs

92
trust score
Avg Security Score
88/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect Suffusion Shortcodes

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/suffusion-shortcodes/include/css/admin.css
Version Parameters
suffusion-shortcodes/include/css/admin.css?ver=http://fonts.googleapis.com/css?family=Dosis?ver=

HTML / DOM Fingerprints

CSS Classes
suf-ip-wrappersip-return-messagesuf-widgetsuf-widget-1csuf-widget-2csuf-widget-3csuf-widget-4csuf-widget-5c
HTML Comments
<!-- widget start --><!-- widget end -->
Data Attributes
name="suffusion_shortcode_options[enable_audio_shortcode]"name="suffusion_shortcode_options[adhoc_wareas]"name="suffusion_shortcode_options[adhoc_column_counts][value="
JS Globals
suffusion_shortcode_options
Shortcode Output
[suffusion-categories][suffusion-the-year][suffusion-site-link][suffusion-the-author]
FAQ

Frequently Asked Questions about Suffusion Shortcodes