
User Shortcodes Security & Risk Analysis
wordpress.org/plugins/user-shortcodesAdd a simple list of shortcodes to WordPress in order to display the current user information.
Is User Shortcodes Safe to Use in 2026?
Generally Safe
Score 85/100User Shortcodes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "user-shortcodes" plugin v1.0.1 exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, proper use of prepared statements for all SQL queries, and 100% output escaping indicate diligent secure coding practices. Furthermore, the lack of file operations and external HTTP requests minimizes potential attack vectors. The plugin also scores well on authentication and authorization, with no identified unprotected entry points, nonce checks, or capability checks that are a common source of vulnerabilities in WordPress plugins.
However, the analysis does highlight some areas that, while not demonstrating active vulnerabilities in this version, represent potential risks that could be exploited if the plugin evolves. The presence of six shortcodes as entry points, even without direct authentication checks listed in the report, means that any flaws within these shortcodes themselves could be a pathway for attackers. The absence of recorded vulnerabilities in its history is positive, suggesting the developers have historically maintained a secure codebase. Nevertheless, this history, combined with the potential for issues within the shortcodes, warrants continued vigilance.
Key Concerns
- Shortcodes as potential entry points without explicit auth checks
- No recorded nonce checks for entry points
- No recorded capability checks for entry points
User Shortcodes Security Vulnerabilities
User Shortcodes Release Timeline
User Shortcodes Code Analysis
User Shortcodes Attack Surface
Shortcodes 6
Maintenance & Trust
User Shortcodes Maintenance & Trust
Maintenance Signals
Community Trust
User Shortcodes Alternatives
Gleam Shortcodes
gleam-shortcodes
Add a simple list of shortcodes to WordPress in order to display the current user information.
User Role Editor
user-role-editor
User Role Editor WordPress plugin makes user roles and capabilities changing easy. Edit/add/delete WordPress user roles and capabilities.
Simple History – Track, Log, and Audit WordPress Changes
simple-history
Track changes and user activities on your WordPress site. See who created a page, uploaded an attachment, and more, for a complete audit trail.
WP Activity Log
wp-security-audit-log
The #1 user-rated activity log plugin for event logging, activity monitoring and change tracking.
Activity Log – Monitor & Record User Changes
aryo-activity-log
This top rated Activity Log plugin helps you monitor & log all changes and actions on your WordPress site, so you can remain secure and organized.
User Shortcodes Developer Profile
6 plugins · 2K total installs
How We Detect User Shortcodes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
[currentuser_username][currentuser_useremail][currentuser_firstname][currentuser_lastname]