
User Profile Shortcode Display Security & Risk Analysis
wordpress.org/plugins/user-profile-shortcode-displayThis plugin simply used to show the user data of current user and another by using shortcodes.
Is User Profile Shortcode Display Safe to Use in 2026?
Generally Safe
Score 100/100User Profile Shortcode Display has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "user-profile-shortcode-display" v1.1 plugin exhibits a generally positive security posture based on the provided static analysis. The absence of dangerous functions, properly escaped output, and SQL queries exclusively using prepared statements are strong indicators of good development practices. Furthermore, the plugin has no recorded vulnerabilities, including CVEs, which suggests a history of secure development and maintenance. The limited attack surface, primarily consisting of shortcodes, and the lack of direct external interactions also contribute to its favorable security profile.
However, a significant concern arises from the complete lack of nonce checks and capability checks across all entry points. While there are no AJAX handlers or REST API routes that are immediately flagged as unprotected, the absence of these fundamental WordPress security mechanisms leaves the shortcodes potentially vulnerable to certain types of attacks if the data processed by them is not sufficiently sanitized or if they can be triggered in an unintended context. This oversight, despite the otherwise clean code, represents a potential weakness that could be exploited in conjunction with other factors or if the plugin's functionality evolves in ways that introduce new risks.
Key Concerns
- Missing nonce checks on all entry points
- Missing capability checks on all entry points
User Profile Shortcode Display Security Vulnerabilities
User Profile Shortcode Display Release Timeline
User Profile Shortcode Display Code Analysis
Output Escaping
User Profile Shortcode Display Attack Surface
Shortcodes 3
WordPress Hooks 4
Maintenance & Trust
User Profile Shortcode Display Maintenance & Trust
Maintenance Signals
Community Trust
User Profile Shortcode Display Alternatives
Export User Data
export-user-data
Export users data and metadata to a csv or Excel file
PiWeb Export Customers Users & Guest customer to CSV for WooCommerce
export-woocommerce-customer-list
Export WooCommerce customer list CSV, export WooCommerce guest customer list CSV, export WordPress users CSV, Product Customer List for WooCommerce
Better Admin Users Search
better-admin-users-search
Improve users admin search
NHR Advanced Options Table Manager & Autoload Optimizer
nhrrob-options-table-manager
Optimize WordPress with Advanced Option History, Autoload Health Checks, and Automated Cleanup. Boost performance by reducing database bloat.
Import User Meta Data from CSV
add-user-metadata
Bulk import user meta data from a text list ( csv ) - checking for missing users & existing usermeta data to avoid duplicates.
User Profile Shortcode Display Developer Profile
41 plugins · 25K total installs
How We Detect User Profile Shortcode Display
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/user-profile-shortcode-display/assets/css/userprsh_admin.cssuser-profile-shortcode-display/assets/css/userprsh_admin.css?ver=1.1HTML / DOM Fingerprints
<div class="userprsh-profile-display"><div class="userprsh-profile-avatar"><img src="" alt="User Avatar" class="userprsh-avatar-img">