
TR All Shortcodes Security & Risk Analysis
wordpress.org/plugins/tr-all-shortcodesList All Shortcodes, Find shortcode on post content used.
Is TR All Shortcodes Safe to Use in 2026?
Generally Safe
Score 85/100TR All Shortcodes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "tr-all-shortcodes" plugin exhibits a concerning security posture despite a clean vulnerability history. While the static analysis reveals a minimal attack surface and no known CVEs, the code signals raise significant red flags. A notable issue is the complete absence of output escaping, meaning any data processed by the plugin could be injected into the page without proper sanitization, leading to potential Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the single SQL query is not using prepared statements, increasing the risk of SQL injection. The taint analysis confirms a critical flow with an unsanitized path, directly correlating with the lack of escaping and raw SQL. The absence of nonce and capability checks, while not directly exploitable with the current attack surface, indicates a general lack of robust security implementations. The clean vulnerability history is positive, but it may not reflect the underlying code weaknesses that could be exploited given the identified issues.
Key Concerns
- 0% output escaping
- 1 SQL query, 0% prepared
- 1 unsanitized path in taint analysis
- No nonce checks
- No capability checks
TR All Shortcodes Security Vulnerabilities
TR All Shortcodes Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
TR All Shortcodes Attack Surface
WordPress Hooks 2
Maintenance & Trust
TR All Shortcodes Maintenance & Trust
Maintenance Signals
Community Trust
TR All Shortcodes Alternatives
WP Shortcodes Plugin — Shortcodes Ultimate
shortcodes-ultimate
A comprehensive collection of visual components for your site
MW WP Form
mw-wp-form
MW WP Form is shortcode base contact form plugin. This plugin have many features. For example you can use many validation rules, inquiry data saving, …
Shortcoder — Create Shortcodes for Anything
shortcoder
Create custom "Shortcodes" easily for HTML, JavaScript, CSS code snippets and use the shortcodes within posts, pages & widgets
Display Posts – Easy lists, grids, navigation, and more
display-posts-shortcode
Add a listing of content on your website using a simple shortcode. Filter the results by category, author, and more.
WP Show Posts
wp-show-posts
Add posts to your website from any post type using a simple shortcode.
TR All Shortcodes Developer Profile
3 plugins · 30 total installs
How We Detect TR All Shortcodes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tr-all-shortcodes/css/style.css/wp-content/plugins/tr-all-shortcodes/js/script.js/wp-content/plugins/tr-all-shortcodes/js/script.jstr-all-shortcodes/css/style.css?ver=tr-all-shortcodes/js/script.js?ver=