
User Access Shortcodes Security & Risk Analysis
wordpress.org/plugins/user-access-shortcodesThe simplest way of controlling who sees what in your posts/pages. Restrict content to logged in users only (or guests, or by roles) with simple short …
Is User Access Shortcodes Safe to Use in 2026?
Generally Safe
Score 100/100User Access Shortcodes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'user-access-shortcodes' plugin version 2.3 exhibits a generally good security posture with several positive attributes. Notably, all identified entry points, which consist solely of shortcodes, are protected by capability checks. The plugin also demonstrates robust data handling by exclusively using prepared statements for its SQL queries, indicating a commitment to preventing SQL injection vulnerabilities. Furthermore, the absence of known CVEs and a clean vulnerability history suggest a well-maintained and secure codebase. However, a significant concern arises from the output escaping analysis, where 100% of identified outputs are not properly escaped. This opens the door to cross-site scripting (XSS) vulnerabilities, as user-supplied data displayed by the shortcodes could be manipulated to execute malicious scripts in the user's browser. The lack of taint analysis data also means that complex data flow vulnerabilities might not have been detected by the static analysis, though this is less of a direct concern given the other findings.
Key Concerns
- 100% of outputs not properly escaped
User Access Shortcodes Security Vulnerabilities
User Access Shortcodes Code Analysis
Output Escaping
User Access Shortcodes Attack Surface
Shortcodes 4
WordPress Hooks 4
Maintenance & Trust
User Access Shortcodes Maintenance & Trust
Maintenance Signals
Community Trust
User Access Shortcodes Alternatives
User Timer
user-timer
Tracks the activity of logged-in users by measuring how long their browser stays active on the site.
Kings Different Content for Members
kings-different-content-for-members
This will add allow you to show different texts only for logged in users, while normal texts for normal visitors.
User Recent Search History
user-recent-search-history
This plugin is to show user's recent search history.
Logged In Users
logged-in-users
Adds a dashboard widget showing which users are currently logged in.
When Last Login
when-last-login
Show a users last login date by creating a sortable column in your WordPress users list.
User Access Shortcodes Developer Profile
8 plugins · 59K total installs
How We Detect User Access Shortcodes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/user-access-shortcodes/img/uasc-icon.png/wp-content/plugins/user-access-shortcodes/js/uasc-mce-button.jsuser-access-shortcodes/style.css?ver=user-access-shortcodes/js/uasc-mce-button.js?ver=HTML / DOM Fingerprints
mce-i-uasc-mce-icon[UAS_guest][/UAS_guest][UAS_loggedin][/UAS_loggedin]