
Unused Shortcodes Security & Risk Analysis
wordpress.org/plugins/unused-shortcodesA plugin to check to see if a shortcode is in use.
Is Unused Shortcodes Safe to Use in 2026?
Generally Safe
Score 92/100Unused Shortcodes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "unused-shortcodes" v1.0.6 plugin exhibits a generally positive security posture based on the provided static analysis. The plugin has no known CVEs and has not historically had any recorded vulnerabilities, which is a strong indicator of good development practices and a secure codebase. The attack surface is minimal, consisting of only one shortcode, and importantly, there are no unauthenticated entry points, which significantly reduces the risk of unauthorized access or code execution.
However, there are areas for improvement. The most significant concern is the output escaping, where only 33% of outputs are properly escaped. This indicates a potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data or dynamically generated content is not properly sanitized before being displayed. While taint analysis did not reveal any critical or high-severity flows, the lack of proper output escaping means that even seemingly innocuous data could be exploited. The absence of nonce checks and capability checks on the shortcode, while not immediately alarming due to the limited attack surface, could become a concern if the shortcode's functionality were to evolve or interact with sensitive data.
In conclusion, the "unused-shortcodes" v1.0.6 plugin is largely secure, especially given its clean vulnerability history and minimal authenticated attack surface. The primary weakness lies in the inconsistent output escaping, which presents a tangible risk of XSS. Addressing this output escaping issue would further solidify the plugin's security. The lack of nonce and capability checks, while not a critical flaw in its current state, is a practice that could be improved for future-proofing.
Key Concerns
- Low percentage of properly escaped output
Unused Shortcodes Security Vulnerabilities
Unused Shortcodes Code Analysis
Output Escaping
Unused Shortcodes Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
Unused Shortcodes Maintenance & Trust
Maintenance Signals
Community Trust
Unused Shortcodes Alternatives
Abdiel Global Variables
abdiel-global-variables
Create reusable global text values (phones, links, short messages, custom values, etc.) and use them anywhere via simple shortcodes.
Captain Hooks
captain-hooks
Captain Hooks is a WordPress plugin that provides developers with a comprehensive view of all actions, filters, and shortcodes of their environment.
Column Shortcodes
column-shortcodes
Adds shortcodes to easily create columns in your posts or pages.
Apollo13 Framework Extensions
apollo13-framework-extensions
Adds custom post types, shortcodes and some features that are used in themes built on Apollo13 Framework.
Futurio Extra
futurio-extra
Futurio Extra add extra features to Futurio theme like widgets, WooCommerce options, Elementor widgets, one click demo import and much more.
Unused Shortcodes Developer Profile
15 plugins · 13K total installs
How We Detect Unused Shortcodes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/unused-shortcodes/options.phpHTML / DOM Fingerprints
<strong>[]</strong>is currently in use in the following page(s)/post(s):No posts found using the shortcode