Shortcodes 1.0.25 / Security
Shortcode access and security
Apply guest, member, role, and capability rules to mapped commands.
Each mapping declares its audience. Social Terminal hides unavailable commands and the mapping handler repeats the same policy at execution.
The owning shortcode may perform additional permission checks; preserve them. Never use a mapping to expose administrator pages, secrets, private account data, nonce-bearing forms, arbitrary PHP, or a shortcode whose output changes server state without an independently reviewed contract.
Test guest, normal member, intended role, denied role, and administrator. A denied actor must not learn hidden attributes or private rendered output.
Shortcodes is Free-only. Installing a paid bridge or host does not broaden a mapping’s authority.
