
WP Shortcodes API Security & Risk Analysis
wordpress.org/plugins/wordpress-shortcodes-apiStores information about available shortcodes as an option and provides a method to easily add a media button with configurable options.
Is WP Shortcodes API Safe to Use in 2026?
Generally Safe
Score 85/100WP Shortcodes API has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wordpress-shortcodes-api plugin v0.8 exhibits a generally positive security posture, with no critical or high-severity vulnerabilities identified in its history or static analysis. The complete absence of dangerous functions, SQL injection risks (all queries use prepared statements), file operations, and external HTTP requests is commendable. The plugin also avoids common pitfalls like bundled libraries. However, a significant concern arises from the output escaping, where only 31% of outputs are properly escaped. This leaves a considerable portion of the plugin's output potentially vulnerable to cross-site scripting (XSS) attacks if user-supplied data is not sufficiently sanitized before being displayed. While the static analysis reports no direct taint flows or unsanitized paths, the low output escaping percentage represents a tangible risk that warrants attention. The lack of any recorded vulnerabilities in its history might indicate good development practices or a limited attack surface, but the insufficient output escaping is a clear weakness that could be exploited.
Key Concerns
- Insufficient output escaping
WP Shortcodes API Security Vulnerabilities
WP Shortcodes API Code Analysis
Output Escaping
WP Shortcodes API Attack Surface
Shortcodes 2
WordPress Hooks 2
Maintenance & Trust
WP Shortcodes API Maintenance & Trust
Maintenance Signals
Community Trust
WP Shortcodes API Alternatives
WP Shortcodes Plugin — Shortcodes Ultimate
shortcodes-ultimate
A comprehensive collection of visual components for your site
MW WP Form
mw-wp-form
MW WP Form is shortcode base contact form plugin. This plugin have many features. For example you can use many validation rules, inquiry data saving, …
Shortcoder — Create Shortcodes for Anything
shortcoder
Create custom "Shortcodes" easily for HTML, JavaScript, CSS code snippets and use the shortcodes within posts, pages & widgets
Display Posts – Easy lists, grids, navigation, and more
display-posts-shortcode
Add a listing of content on your website using a simple shortcode. Filter the results by category, author, and more.
WP Show Posts
wp-show-posts
Add posts to your website from any post type using a simple shortcode.
WP Shortcodes API Developer Profile
2 plugins · 20 total installs
How We Detect WP Shortcodes API
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wordpress-shortcodes-api/js/shortcode-media-button.js/wp-content/plugins/wordpress-shortcodes-api/css/shortcode-media-button.css/wp-content/plugins/wordpress-shortcodes-api/js/shortcode-media-button.jswordpress-shortcodes-api/css/shortcode-media-button.css?ver=wordpress-shortcodes-api/js/shortcode-media-button.js?ver=HTML / DOM Fingerprints
data-shortcodedata-titledata-icondata-introdata-input-attsWP_Shortcodes_Media_Button