Total Findings
614
Security Grade
Active Installs
400K+
Coding Score
100/100
Shortcodes Ultimate is a comprehensive shortcode plugin with generally solid security practices. The codebase demonstrates proper use of WordPress APIs, nonce verification, capability checks, and input sanitization. However, there are several concerns that elevate the risk level: unescaped output in template files, potential CSRF vulnerabilities in notice dismissal handlers, and missing capability checks in some admin functionality. The plugin handles 'unsafe features' appropriately by automatically disabling them when multiple users exist. Most findings are medium-severity issues that should be addressed to improve the security posture.
Show your audit status in your README or website.
<a href="https://wphealthkit.com/directory/shortcodes-ultimate"><img src="https://wphealthkit.com/api/badge/shortcodes-ultimate" alt="WP Shortcodes Plugin — Shortcodes Ultimate security audit by WP HealthKit" /></a>
Claim this listing to get a Verified badge, control public audits, and get automatic re-scans.
Claim This PluginGet a comprehensive security audit for your WordPress plugin or theme. Upload your zip and get results in minutes.
Start Free AuditProduction Ready
Not ReadyWP.org Ready
NoCompliance
Non-CompliantCoding Standards
100/100