
WP Shortcode by MyThemeShop Security & Risk Analysis
wordpress.org/plugins/wp-shortcodeWP Shortcode is a premium WP plugin for free, that provides easy to use over 24 shortcodes. You can easily add buttons, alerts, videos and more.
Is WP Shortcode by MyThemeShop Safe to Use in 2026?
Generally Safe
Score 85/100WP Shortcode by MyThemeShop has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "wp-shortcode" plugin v1.4.17 exhibits a mixed security posture. On the positive side, the code shows good practices regarding SQL queries, exclusively using prepared statements, and there are no identified critical or high-severity taint flows. The plugin also incorporates nonce checks and capability checks, which are essential security measures. However, concerns arise from the presence of one AJAX handler without authentication, presenting a direct attack vector. Furthermore, a significant portion of output (23%) is not properly escaped, which could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not handled carefully.
The vulnerability history reveals one past medium-severity CVE, specifically a Cross-Site Request Forgery (CSRF). While this vulnerability is currently patched and the plugin has no outstanding unpatched CVEs, the past occurrence of CSRF highlights a potential area for developer vigilance. The large number of shortcodes (41) also contributes to a broad attack surface, although most entry points appear to be secured.
In conclusion, while the plugin demonstrates some strong security fundamentals like prepared SQL statements and the absence of critical taint issues, the unprotected AJAX endpoint and the unescaped output represent immediate risks that require attention. The past CSRF vulnerability, though resolved, suggests a history that warrants continued security monitoring.
Key Concerns
- Unprotected AJAX handler
- Significant unescaped output (23%)
- Past medium CVE (CSRF)
WP Shortcode by MyThemeShop Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WP Shortcode by MyThemeShop <= 1.4.16 - Cross-Site Request Forgery
WP Shortcode by MyThemeShop Release Timeline
WP Shortcode by MyThemeShop Code Analysis
Bundled Libraries
Output Escaping
WP Shortcode by MyThemeShop Attack Surface
AJAX Handlers 1
Shortcodes 41
WordPress Hooks 14
Maintenance & Trust
WP Shortcode by MyThemeShop Maintenance & Trust
Maintenance Signals
Community Trust
WP Shortcode by MyThemeShop Alternatives
Bootstrap Shortcodes
bootstrap-shortcodes
Wordpress plugin to add shortcodes for Twitter Bootstrap 3.3
Arconix Shortcodes
arconix-shortcodes
Arconix Shortcodes provides a number of useful design elements like buttons, boxes, tabs and toggles to help compliment any website.
Rescue Shortcodes
rescue-shortcodes
A lightweight WordPress shortcodes plugin.
Shortcode Revolution
shortcode-revolution
Shortcode everything. The low code / no code tool for WordPress developers, designers, and power users. /*** This program is free software: you can …
Foundation Shortcodes
foundation-shortcodes
Adds WordPress shortcode support for Foundation layouts and UI elements - to be used with themes built with Foundation 5.
WP Shortcode by MyThemeShop Developer Profile
7 plugins · 38K total installs
How We Detect WP Shortcode by MyThemeShop
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-shortcode/css/tipsy.css/wp-content/plugins/wp-shortcode/css/wp-shortcode.css/wp-content/plugins/wp-shortcode/js/jquery.tipsy.js/wp-content/plugins/wp-shortcode/js/wp-shortcode.js/wp-content/plugins/wp-shortcode/js/admin.js/wp-content/plugins/wp-shortcode/js/jquery.tipsy.js/wp-content/plugins/wp-shortcode/js/wp-shortcode.js/wp-content/plugins/wp-shortcode/js/admin.jswp-shortcode/css/tipsy.css?ver=wp-shortcode/css/wp-shortcode.css?ver=wp-shortcode/js/jquery.tipsy.js?ver=wp-shortcode/js/wp-shortcode.js?ver=wp-shortcode/js/admin.js?ver=HTML / DOM Fingerprints
buttonsbtn_brownbtn_bluebtn_greenbtn_redbtn_whitebtn_yellowalert-note+20 more<!-- Shortcode Button <!-- Tabs <!-- Toggle <!-- Divider +2 moredata-tabdata-toggleMTS_Shortcodes<a hrefclass="buttons btn_<div class="button-center"><div class="alert alert-