Twitter's Bootstrap Shortcodes Ultimate Add-on Security & Risk Analysis

wordpress.org/plugins/twitters-bootstrap-shortcodes-ultimate

Add short codes for Twitter's Bootstrap 3 CSS and components to your site add-on for Shortcodes Ultimate.

300 active installs v1.0.4 PHP + WP 3.6+ Updated Jan 5, 2014
short-codesshortcodes-ultimatetwitters-bootstrap-3
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Twitter's Bootstrap Shortcodes Ultimate Add-on Safe to Use in 2026?

Generally Safe

Score 85/100

Twitter's Bootstrap Shortcodes Ultimate Add-on has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The static analysis of "twitters-bootstrap-shortcodes-ultimate" v1.0.4 reveals a remarkably small attack surface, with no apparent AJAX handlers, REST API routes, shortcodes, or cron events that could be exploited. The code also demonstrates good practices by avoiding dangerous functions, external HTTP requests, file operations, and by using prepared statements for all its SQL queries. However, a significant concern is the complete lack of output escaping, meaning any data outputted by the plugin could potentially be rendered as code or malicious scripts in the user's browser, leading to Cross-Site Scripting (XSS) vulnerabilities. The absence of nonce and capability checks across all entry points further exacerbates this risk, as unauthorized users could potentially trigger actions or view sensitive information if any were present. The vulnerability history is clean, indicating no previously disclosed security flaws, which is a positive sign. Despite the limited attack surface and good SQL practices, the complete lack of output escaping and insufficient authorization checks on potential entry points represent critical security weaknesses that need immediate attention.

Key Concerns

  • Outputs not properly escaped
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Twitter's Bootstrap Shortcodes Ultimate Add-on Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Twitter's Bootstrap Shortcodes Ultimate Add-on Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

Twitter's Bootstrap Shortcodes Ultimate Add-on Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actioninitinc\jbst-shortcodes.php:8
filterwidget_textinc\jbst-shortcodes.php:10
filterinittwitters-bootstrap-shortcodes-ultimate.php:60
actionadmin_noticestwitters-bootstrap-shortcodes-ultimate.php:108
filtersu/data/groupstwitters-bootstrap-shortcodes-ultimate.php:123
filtersu/data/shortcodestwitters-bootstrap-shortcodes-ultimate.php:124
Maintenance & Trust

Twitter's Bootstrap Shortcodes Ultimate Add-on Maintenance & Trust

Maintenance Signals

WordPress version tested3.9.40
Last updatedJan 5, 2014
PHP min version
Downloads14K

Community Trust

Rating100/100
Number of ratings3
Active installs300
Developer Profile

Twitter's Bootstrap Shortcodes Ultimate Add-on Developer Profile

bassjobsen

2 plugins · 310 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Twitter's Bootstrap Shortcodes Ultimate Add-on

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/twitters-bootstrap-shortcodes-ultimate/css/bootstrap-shortcodes-ultimate.css/wp-content/plugins/twitters-bootstrap-shortcodes-ultimate/js/bootstrap-shortcodes-ultimate.js
Script Paths
/wp-content/plugins/twitters-bootstrap-shortcodes-ultimate/js/bootstrap-shortcodes-ultimate.js
Version Parameters
twitters-bootstrap-shortcodes-ultimate/css/bootstrap-shortcodes-ultimate.css?ver=twitters-bootstrap-shortcodes-ultimate/js/bootstrap-shortcodes-ultimate.js?ver=

HTML / DOM Fingerprints

CSS Classes
btn-groupbtnlabelbadgepre-scrollableprettyprintrow
Data Attributes
data-su-cmpt
Shortcode Output
<div class="btn-group"><a href="class="btn <i class="glyphicon glyphicon-
FAQ

Frequently Asked Questions about Twitter's Bootstrap Shortcodes Ultimate Add-on