Skip to content

Shortcodes 1.0.25 / Security

Shortcode access and security

Apply guest, member, role, and capability rules to mapped commands.

Each mapping declares its audience. Social Terminal hides unavailable commands and the mapping handler repeats the same policy at execution.

The owning shortcode may perform additional permission checks; preserve them. Never use a mapping to expose administrator pages, secrets, private account data, nonce-bearing forms, arbitrary PHP, or a shortcode whose output changes server state without an independently reviewed contract.

Test guest, normal member, intended role, denied role, and administrator. A denied actor must not learn hidden attributes or private rendered output.

Shortcodes is Free-only. Installing a paid bridge or host does not broaden a mapping’s authority.

Was this documentation helpful?Your response helps us improve this page.