
URL & Path Shortcodes Security & Risk Analysis
wordpress.org/plugins/url-path-shortcodesThis is a simple plugin that allows you to use common WordPress URL's and Paths in the post editor using shortcodes.
Is URL & Path Shortcodes Safe to Use in 2026?
Generally Safe
Score 85/100URL & Path Shortcodes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "url-path-shortcodes" plugin v1.0 exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, SQL queries that are all prepared, and properly escaped output are excellent indicators of secure coding practices. Furthermore, the lack of file operations and external HTTP requests minimizes potential attack vectors. The plugin also demonstrates a good approach to handling its attack surface by having 0 unprotected entry points. The vulnerability history being completely clean further reinforces its current security standing.
While the static analysis is overwhelmingly positive, a notable area of concern is the complete absence of nonce checks and capability checks. For shortcodes, especially those that might interact with user data or perform sensitive actions, these checks are crucial for preventing Cross-Site Request Forgery (CSRF) attacks and ensuring that only authorized users can trigger them. Although the current version has no recorded vulnerabilities, the lack of these fundamental security mechanisms represents a potential weakness that could be exploited if a vulnerability were to be introduced in a future update or if the shortcodes themselves were to become more complex or sensitive.
In conclusion, the plugin demonstrates robust security in its current implementation, adhering to good practices in data handling and query preparation. However, the complete omission of nonce and capability checks for its shortcodes is a significant oversight that, while not currently manifesting as a known vulnerability, leaves the plugin susceptible to specific types of attacks. Addressing these checks should be a priority to ensure a truly secure and resilient plugin.
Key Concerns
- Missing nonce checks on shortcodes
- Missing capability checks on shortcodes
URL & Path Shortcodes Security Vulnerabilities
URL & Path Shortcodes Code Analysis
URL & Path Shortcodes Attack Surface
Shortcodes 16
Maintenance & Trust
URL & Path Shortcodes Maintenance & Trust
Maintenance Signals
Community Trust
URL & Path Shortcodes Alternatives
UT WordPress Shortcodes
ut-wordpress-shortcodes
Plugin to create useful shortcodes for easy site management.
Column Shortcodes
column-shortcodes
Adds shortcodes to easily create columns in your posts or pages.
Apollo13 Framework Extensions
apollo13-framework-extensions
Adds custom post types, shortcodes and some features that are used in themes built on Apollo13 Framework.
Futurio Extra
futurio-extra
Futurio Extra add extra features to Futurio theme like widgets, WooCommerce options, Elementor widgets, one click demo import and much more.
ND Shortcodes
nd-shortcodes
The plugin adds some useful components to your page builder ( Elementor or WP Bakery Page Builder ). All components are full responsive and retina rea …
URL & Path Shortcodes Developer Profile
6 plugins · 260 total installs
How We Detect URL & Path Shortcodes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
[home_url][site_url][admin_url][network_home_url]