WP Amara Shortcode Security & Risk Analysis

wordpress.org/plugins/wp-amara-shortcode

A simple wordpress plugin to enable Amara.org shortcode

10 active installs v1.2 PHP + WP 3.0.1+ Updated Unknown
amaraamara-orgsubtitlesvideo
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Amara Shortcode Safe to Use in 2026?

Generally Safe

Score 100/100

WP Amara Shortcode has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The wp-amara-shortcode plugin version 1.2 exhibits a strong security posture based on the provided static analysis. The code demonstrates adherence to secure coding practices, with no identified dangerous functions, all SQL queries using prepared statements, and all output properly escaped. Furthermore, the absence of file operations and external HTTP requests minimizes potential attack vectors. The plugin also has a clean vulnerability history, with no known CVEs recorded, which is a positive indicator of its security reliability. The static analysis reveals a minimal attack surface consisting of a single shortcode, and importantly, no AJAX handlers or REST API routes are exposed without proper authentication checks, significantly reducing the risk of unauthorized access or manipulation. The lack of any identified taint flows with unsanitized paths further reinforces the perception of a well-secured plugin. However, the absence of nonce checks and capability checks on its sole entry point (the shortcode) presents a potential, albeit likely low, risk of CSRF or other forms of unauthorized execution if the shortcode itself performs sensitive actions that are not inherently protected by WordPress's user role management. This is the primary area of concern in an otherwise robust security profile.

Key Concerns

  • Missing nonce check on shortcode
  • Missing capability check on shortcode
Vulnerabilities
None known

WP Amara Shortcode Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP Amara Shortcode Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

WP Amara Shortcode Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[amara] wp_amara_shortcode.php:37
Maintenance & Trust

WP Amara Shortcode Maintenance & Trust

Maintenance Signals

WordPress version tested3.7.41
Last updatedUnknown
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

WP Amara Shortcode Developer Profile

d79

3 plugins · 80 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Amara Shortcode

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
/wp-content/plugins/wp-amara-shortcode/embed.js

HTML / DOM Fingerprints

Shortcode Output
<script type="text/javascript" src="http://s3.www.universalsubtitles.org/embed.js">
FAQ

Frequently Asked Questions about WP Amara Shortcode