
Twitter's Bootstrap Shortcodes Ultimate Add-on Security & Risk Analysis
wordpress.org/plugins/twitters-bootstrap-shortcodes-ultimateAdd short codes for Twitter's Bootstrap 3 CSS and components to your site add-on for Shortcodes Ultimate.
Is Twitter's Bootstrap Shortcodes Ultimate Add-on Safe to Use in 2026?
Generally Safe
Score 85/100Twitter's Bootstrap Shortcodes Ultimate Add-on has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of "twitters-bootstrap-shortcodes-ultimate" v1.0.4 reveals a remarkably small attack surface, with no apparent AJAX handlers, REST API routes, shortcodes, or cron events that could be exploited. The code also demonstrates good practices by avoiding dangerous functions, external HTTP requests, file operations, and by using prepared statements for all its SQL queries. However, a significant concern is the complete lack of output escaping, meaning any data outputted by the plugin could potentially be rendered as code or malicious scripts in the user's browser, leading to Cross-Site Scripting (XSS) vulnerabilities. The absence of nonce and capability checks across all entry points further exacerbates this risk, as unauthorized users could potentially trigger actions or view sensitive information if any were present. The vulnerability history is clean, indicating no previously disclosed security flaws, which is a positive sign. Despite the limited attack surface and good SQL practices, the complete lack of output escaping and insufficient authorization checks on potential entry points represent critical security weaknesses that need immediate attention.
Key Concerns
- Outputs not properly escaped
- No nonce checks
- No capability checks
Twitter's Bootstrap Shortcodes Ultimate Add-on Security Vulnerabilities
Twitter's Bootstrap Shortcodes Ultimate Add-on Code Analysis
Output Escaping
Twitter's Bootstrap Shortcodes Ultimate Add-on Attack Surface
WordPress Hooks 6
Maintenance & Trust
Twitter's Bootstrap Shortcodes Ultimate Add-on Maintenance & Trust
Maintenance Signals
Community Trust
Twitter's Bootstrap Shortcodes Ultimate Add-on Alternatives
SS Font Awesome Icon
ss-font-awesome-icon
Easiest way to integrate Font Awesome Icon in any post or widget.
PDF Shortcodes Ultimate
pdf-shortcodes-ultimate
Embed PDF documents in your article or page with this "PDF" shortcode for Shortcodes Ultimate.
insertTime
inserttime
A simple wordpress plugin that adds a shorcode [time] tp insert your local time at page loading in a post.
Twitter's Bootstrap Shortcodes Ultimate Add-on Developer Profile
2 plugins · 310 total installs
How We Detect Twitter's Bootstrap Shortcodes Ultimate Add-on
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/twitters-bootstrap-shortcodes-ultimate/css/bootstrap-shortcodes-ultimate.css/wp-content/plugins/twitters-bootstrap-shortcodes-ultimate/js/bootstrap-shortcodes-ultimate.js/wp-content/plugins/twitters-bootstrap-shortcodes-ultimate/js/bootstrap-shortcodes-ultimate.jstwitters-bootstrap-shortcodes-ultimate/css/bootstrap-shortcodes-ultimate.css?ver=twitters-bootstrap-shortcodes-ultimate/js/bootstrap-shortcodes-ultimate.js?ver=HTML / DOM Fingerprints
btn-groupbtnlabelbadgepre-scrollableprettyprintrowdata-su-cmpt<div class="btn-group"><a href="class="btn <i class="glyphicon glyphicon-