WooCommerce Shortcodes Security & Risk Analysis

wordpress.org/plugins/woocommerce-shortcodes

Adds a button in TinyMCE editor allowing use of WooCommerce shortcodes. Beautifully.

10K active installs v1.0.0 PHP + WP 3.9+ Updated Aug 27, 2020
shortcodeswoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WooCommerce Shortcodes Safe to Use in 2026?

Generally Safe

Score 85/100

WooCommerce Shortcodes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The WooCommerce Shortcodes plugin v1.0.0 exhibits a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, raw SQL queries, or external HTTP requests is a significant positive indicator. Furthermore, the high percentage of properly escaped output and the presence of capability checks suggest good development practices in preventing common web vulnerabilities like XSS and privilege escalation. The plugin also has no recorded vulnerability history, including CVEs, which further bolsters confidence in its current security. This indicates a mature and well-maintained codebase from a security perspective.

Vulnerabilities
None known

WooCommerce Shortcodes Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WooCommerce Shortcodes Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
58 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

98% escaped59 total outputs
Attack Surface

WooCommerce Shortcodes Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionadmin_headincludes\class-wc-shortcodes-admin.php:15
filtertiny_mce_versionincludes\class-wc-shortcodes-admin.php:16
filtermce_external_languagesincludes\class-wc-shortcodes-admin.php:17
actionadmin_enqueue_scriptsincludes\class-wc-shortcodes-admin.php:18
filtermce_external_pluginsincludes\class-wc-shortcodes-admin.php:30
filtermce_buttonsincludes\class-wc-shortcodes-admin.php:31
actioninitwoocommerce-shortcodes.php:43
actionadmin_noticeswoocommerce-shortcodes.php:54
actionplugins_loadedwoocommerce-shortcodes.php:104
Maintenance & Trust

WooCommerce Shortcodes Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedAug 27, 2020
PHP min version
Downloads336K

Community Trust

Rating86/100
Number of ratings6
Active installs10K
Developer Profile

WooCommerce Shortcodes Developer Profile

Claudio Sanches

17 plugins · 134K total installs

69
trust score
Avg Security Score
85/100
Avg Patch Time
831 days
View full developer profile
Detection Fingerprints

How We Detect WooCommerce Shortcodes

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woocommerce-shortcodes/assets/css/editor.css/wp-content/plugins/woocommerce-shortcodes/assets/js/editor.min.js/wp-content/plugins/woocommerce-shortcodes/assets/js/editor.js
Script Paths
/wp-content/plugins/woocommerce-shortcodes/assets/js/editor.js/wp-content/plugins/woocommerce-shortcodes/assets/js/editor.min.js
Version Parameters
woocommerce-shortcodes/assets/css/editor.css?ver=woocommerce-shortcodes/assets/js/editor.js?ver=woocommerce-shortcodes/assets/js/editor.min.js?ver=

HTML / DOM Fingerprints

JS Globals
window.wc_shortcodes_editor_i18n
FAQ

Frequently Asked Questions about WooCommerce Shortcodes