WP247 Get Option Shortcode Security & Risk Analysis

wordpress.org/plugins/wp247-get-option-shortcode

Include WordPress options anywhere shortcodes are accepted.

10 active installs v1.2 PHP + WP 4.0+ Updated Aug 8, 2021
get_optionoptionsshortcode
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is WP247 Get Option Shortcode Safe to Use in 2026?

Generally Safe

Score 85/100

WP247 Get Option Shortcode has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The wp247-get-option-shortcode v1.2 plugin exhibits a generally good security posture, with no critical or high-severity issues identified in the static analysis or vulnerability history. The presence of nonce and capability checks on all identified entry points (one AJAX handler) is a strong indicator of secure development practices. Furthermore, the complete absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests significantly reduces the potential attack surface. The plugin also demonstrates a clean vulnerability history with zero known CVEs, suggesting a commitment to security and maintenance by its developers.

However, a notable concern arises from the output escaping. With only 24% of the 54 identified outputs being properly escaped, there is a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. While taint analysis did not reveal any unsanitized paths, the high proportion of unescaped output presents a potential weakness that attackers could exploit if they can inject malicious scripts into the data being output by the plugin. This is the primary area requiring attention to further strengthen the plugin's security.

Key Concerns

  • Insufficient output escaping
Vulnerabilities
None known

WP247 Get Option Shortcode Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WP247 Get Option Shortcode Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
41
13 escaped
Nonce Checks
1
Capability Checks
5
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

24% escaped54 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
do_action_wp247xns_client_corequisite_notice_dismiss (admin\wp247xns-client-corequisite-notice\wp247xns-client-corequisite-notice.php:167)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WP247 Get Option Shortcode Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_wp247xns_client_corequisite_notice_dismissadmin\wp247xns-client-corequisite-notice\wp247xns-client-corequisite-notice.php:182
WordPress Hooks 9
actionadmin_enqueue_scriptsadmin\wp247-settings-api\wp247-settings-api.class.php:117
actionadmin_headadmin\wp247-settings-api\wp247-settings-api.class.php:118
actionadmin_menuadmin\wp247-settings-api\wp247-settings-api.class.php:119
actionadmin_initadmin\wp247-settings-api\wp247-settings-api.class.php:120
actionadmin_noticesadmin\wp247xns-client-corequisite-notice\wp247xns-client-corequisite-notice.php:86
actionadmin_enqueue_scriptsadmin\wp247xns-client-corequisite-notice\wp247xns-client-corequisite-notice.php:180
actionadmin_headadmin\wp247xns-client-corequisite-notice\wp247xns-client-corequisite-notice.php:181
actionwp_loadedwp247-get-option-shortcode.php:42
actionadmin_headwp247-get-option-shortcode.php:43
Maintenance & Trust

WP247 Get Option Shortcode Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedAug 8, 2021
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

WP247 Get Option Shortcode Developer Profile

wescleveland

4 plugins · 240 total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP247 Get Option Shortcode

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp247-get-option-shortcode/admin/wp247-settings-api/wp247-settings-api.php/wp-content/plugins/wp247-get-option-shortcode/admin/wp247xns-client-corequisite-notice/wp247xns-client-corequisite-notice.php
Version Parameters
wp247-get-option-shortcode/admin/wp247-settings-api/wp247-settings-api.php?ver=wp247-get-option-shortcode/admin/wp247xns-client-corequisite-notice/wp247xns-client-corequisite-notice.php?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- Program: WP247 Get Option ShortcodePlugin Name: WP247 Get Option ShortcodePlugin Name: WP247 Get Option ShortcodeTell WP247 Extension Notification Client about us+1 more
Shortcode Output
[wp247_get_option option="wp247_get_option
FAQ

Frequently Asked Questions about WP247 Get Option Shortcode