PHP Sandbox (with Shortcodes)
A secure PHP sandbox plugin for WordPress that allows execution of PHP code through shortcodes with proper security measures, user capability checks, and nonce verification.
by Umang Prajapati · github.com/umang48/wp-php-sandbox · website
Install
No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:
wp plugin install https://github.com/umang48/wp-php-sandbox/archive/refs/heads/main.zipA secure PHP sandbox plugin for WordPress that allows safe execution of PHP code through shortcodes with comprehensive security measures.
Description
WP PHP Sandbox (with Shortcodes) is a powerful WordPress plugin that provides a secure environment for executing PHP code through shortcodes. Perfect for developers, educators, and content creators who need to demonstrate PHP code functionality within WordPress posts and pages.
Key Features
- Secure Code Execution: Advanced security measures prevent dangerous functions and unauthorized access
- Multiple Shortcodes: Support for [php_sandbox], [php_code], and [php_execute] shortcodes
- User Permission Control: Configurable user capability requirements
- Execution Limits: Configurable timeout and memory limits for code execution
- Function Whitelisting: Control which PHP functions are allowed
- Comprehensive Logging: Track all code executions for security auditing
- Admin Interface: User-friendly admin panel for configuration and testing
- Syntax Highlighting: Optional code highlighting for better readability
- Multiple Themes: Light and dark theme options
- Nonce Security: Built-in CSRF protection with WordPress nonces
Security Features
- Blocks dangerous functions (file operations, system commands, network functions)
- User capability verification
- Nonce-based request verification
- Execution timeout limits
- Memory usage limits
- Function whitelisting
- Comprehensive execution logging
- Input sanitization and validation
Usage Examples
Basic usage:
[php_sandbox]echo "Hello World!";[/php_sandbox]
With code display:
[php_sandbox show_code="true"] $name = "WordPress"; echo "Hello " . $name . "!"; [/php_sandbox]
With custom theme:
[php_sandbox theme="dark" show_code="true"] $numbers = array(1, 2, 3, 4, 5); echo "Sum: " . array_sum($numbers); [/php_sandbox]
Perfect For
- Developers: Testing code snippets and demonstrations
- Educators: Teaching PHP programming concepts
- Bloggers: Creating interactive coding tutorials
- Documentation: Providing live code examples
Installation
- Upload the plugin files to the
/wp-content/plugins/wp-php-sandbox/directory - Activate the plugin through the 'Plugins' screen in WordPress
- Go to Tools > PHP Sandbox to configure the plugin settings
- Set appropriate user permissions and security settings
- Start using shortcodes in your posts and pages
Frequently Asked Questions
Is this plugin secure?
Yes, the plugin includes comprehensive security measures:
- Blocks dangerous PHP functions
- Enforces user permission checks
- Implements execution limits
- Uses WordPress nonces for CSRF protection
- Logs all executions for auditing
What PHP functions are allowed?
By default, only safe functions are allowed. You can customize the allowed functions list in the plugin settings. Dangerous functions like file operations, system commands, and network functions are blocked.
Can I customize the appearance?
Yes, the plugin supports multiple themes (default and dark) and includes CSS classes for custom styling.
Who can execute PHP code?
By default, users with 'edit_posts' capability can execute code. This is configurable in the plugin settings and can be restricted to higher privilege levels.
Are executions logged?
Yes, all code executions are logged with timestamps, user information, and results for security auditing purposes.
Screenshots
- Admin interface for code execution and testing
- Plugin settings page with security options
- Execution logs for security auditing
- Help page with usage examples
- Shortcode output with code highlighting
- Dark theme example
Changelog
1.0.0
- Initial release
- Secure PHP code execution through shortcodes
- Admin interface for configuration
- Comprehensive security measures
- Execution logging
- Multiple shortcode options
- Theme support
- User permission controls
Security Considerations
This plugin is designed with security in mind, but please note:
- Only grant execution permissions to trusted users
- Regularly review execution logs
- Keep the allowed functions list minimal
- Test thoroughly in a development environment
- Consider additional server-level security measures
Support
For support, feature requests, or bug reports, please visit the plugin's repository or contact the developer.
License
This plugin is licensed under the GPLv2 or later license.