Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PC×
Skip to content
Security

7 Essential Tips for Using Shortcodes in WordPress

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

WordPress shortcodes let you place a registered tag in content and have WordPress replace it with the string returned by a PHP callback. Use a distinctive tag, register one clear handler, set attribute defaults, return rather than echo output, and secure every value for the context where it appears. The tips below cover both using and building shortcodes.

1. Choose a distinctive, lowercase shortcode tag

A shortcode is a registered content macro: WordPress looks for its tag and calls the handler associated with it. Shortcodes can be self-closing, such as [acme_notice], or enclosing, such as [acme_notice]Text here[/acme_notice]. The handler can receive attributes, enclosed content, and the tag name. The API dates to WordPress 2.5. WordPress Shortcode API

Use a lowercase name with a prefix that identifies your plugin or project, for example acme_notice. This reduces the chance that another plugin registers the same name. WordPress advises lowercase shortcode names and cautions against hyphens; follow that documented guidance rather than assuming every punctuation style will behave as intended. Shortcodes – Plugin Handbook

2. Register one clear callback

Register the tag with add_shortcode(). The callback receives the attributes, enclosed content (if any), and shortcode tag. The essential rule is that a later registration for the same tag replaces the earlier callback, so avoid generic names and check for collisions when integrating code from multiple plugins.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
function acme_notice_shortcode( $atts, $content = null, $tag = '' ) {
    return '<div class="acme-notice">Notice</div>';
}
add_shortcode( 'acme_notice', 'acme_notice_shortcode' );

Put registration code in a plugin or another suitable place that loads reliably; a shortcode must be registered when WordPress processes the content. WordPress runs do_shortcode() on the_content by default at priority 11, so shortcode tags in ordinary post content are handled as that content is displayed. A tag placed somewhere that does not run the content filter may need an explicit do_shortcode() call. Shortcode – Common APIs Handbook

3. Define attributes and their defaults

Use shortcode_atts() to keep only supported attributes and supply defaults when an editor omits them. Document the accepted attributes and their expected values so users know what the shortcode supports. Attribute keys are lowercased during processing, so use lowercase keys consistently.

function acme_notice_shortcode( $atts, $content = null ) {
    $atts = shortcode_atts(
        array(
            'type' => 'info',
            'title' => '',
        ),
        $atts,
        'acme_notice'
    );

    // Validate and escape values before adding them to output.
    return '<div class="acme-notice">Notice</div>';
}

For example, the declared options above could be used as [acme_notice type="warning" title="Read this"]. The example establishes defaults and recognized keys; it does not make arbitrary values safe to print. Validate values against the choices your callback actually supports. Shortcodes with Parameters

4. Return output instead of echoing it

A shortcode callback must return its output as a string. WordPress inserts that string where the shortcode appears in the content. Echoing from the callback can send markup to the wrong place in the page output and disrupt the surrounding content.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For small snippets, return a string directly. For more extensive HTML, the API reference illustrates using output buffering to capture generated markup into a string before returning it. Also provide suitable block markup yourself when needed: shortcode output is not automatically processed for paragraphs and line breaks in the same way as surrounding post content. Shortcode – Common APIs Handbook

5. Handle self-closing and enclosing forms deliberately

If your shortcode accepts enclosed content, give the callback’s $content parameter a default of null. That lets the callback distinguish a self-closing use from an enclosing use and decide what each form should do. For example, [acme_notice] may use a default message, while [acme_notice]Custom message[/acme_notice] may use the enclosed text.

Do not assume enclosed content is safe just because it came from a post. Decide whether to treat it as plain text, permit a restricted set of HTML, or process it in another explicitly defined way. The callback is responsible for securing content it incorporates into its output. Enclosing Shortcodes

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

6. Validate inputs and escape output for its context

Sanitization and escaping solve different problems: validate or sanitize incoming values for the use your feature allows, then escape data when generating output. Choose an escaping function based on where the value is placed.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • esc_html() for text inside HTML.
  • esc_attr() for an HTML attribute.
  • esc_url() for a URL.
  • wp_kses_post() when permitted post HTML should be retained.

For instance, a title printed as visible text should be escaped with esc_html(); the same value placed in an attribute needs esc_attr(). A URL should be escaped with esc_url(), and user-provided HTML should not be output unrestricted. Escaping Data and Security

7. Test nesting and parser assumptions

WordPress does not automatically parse shortcodes nested inside the enclosed content of another shortcode in the parser’s single pass. If nested shortcodes are an intentional feature, explicitly call do_shortcode() on the relevant content and document that behavior for editors. Do this only where recursive processing is intended, rather than applying it indiscriminately.

There is also a documented limitation when the same shortcode tag is used in both enclosing and non-enclosing forms in the same content. Test the exact combinations your users will enter instead of assuming mixed forms or nested tags will work like ordinary HTML. Enclosing Shortcodes

Before publishing a shortcode

  • Is the tag distinctive, lowercase, and prefixed?
  • Is the tag registered once with the intended callback?
  • Are accepted attributes and defaults explicit, with values validated?
  • Does the callback return a string and supply its own needed markup?
  • Are enclosed content and generated values handled safely?
  • Have nested and mixed-form uses been tested if the feature supports them?

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.