
Super Cool QRCode Security & Risk Analysis
wordpress.org/plugins/super-cool-qrcodeEasily insert QR codes in your blog, with Widget or Shortcode.
Is Super Cool QRCode Safe to Use in 2026?
Generally Safe
Score 85/100Super Cool QRCode has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "super-cool-qrcode" plugin v0.0.7 exhibits a concerning security posture despite a clean vulnerability history. While the code analysis reveals no immediately apparent dangerous functions, raw SQL queries, or external HTTP requests, and the taint analysis shows no critical or high severity flows, there are significant weaknesses. The most alarming finding is that 100% of its 87 output operations are not properly escaped. This represents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, as malicious input could be rendered directly in the user's browser. Furthermore, the plugin lacks any nonces or capability checks on its single entry point, the shortcode, meaning any logged-in user could potentially trigger its functionality, exacerbating the XSS risk.
Despite the absence of historical CVEs, which might suggest a lack of prior discovery or a very small user base, the identified code-level issues are severe and actionable. The lack of output escaping on such a high number of outputs, combined with the absence of authentication and authorization mechanisms on its sole entry point, creates a clear pathway for exploitation. While the plugin's attack surface is small, its security posture is weakened by these fundamental coding oversights. The developer should prioritize addressing the output escaping and implementing appropriate checks before this plugin is widely adopted or a vulnerability is discovered.
Key Concerns
- 0% output escaping
- No nonce checks on entry points
- No capability checks on entry points
Super Cool QRCode Security Vulnerabilities
Super Cool QRCode Code Analysis
Output Escaping
Super Cool QRCode Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
Super Cool QRCode Maintenance & Trust
Maintenance Signals
Community Trust
Super Cool QRCode Alternatives
Kaya QR Code Generator
kaya-qr-code-generator
Generate QR Code through Widgets and Shortcodes, without any dependencies.
QR Code
qr-code
It lets appear the QR-code of the given site in the slidebar
QR Code Composer – QR Code Generator
qr-code-composer
Generate QR codes for URLs, text, WiFi, email & more in seconds. No setup needed.
QR code MeCard/vCard generator
wp-qrcode-me-v-card
Share your contact information such as emails, phone number and much more through QR code with WordPress using shortcode, widget or by direct link.
Master QR Code Generator – Static QR Code Generator
master-qr-generator
Generates QR codes for every page, post, product, and custom post for the WordPress website.
Super Cool QRCode Developer Profile
1 plugin · 100 total installs
How We Detect Super Cool QRCode
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
scqrcodeid="scqrcode-widget"<img src="http://chart.apis.google.com/chart?cht=qr&chs=width="height="border="