WP Manifestindependent plugin directory
manifest / developer / wp-php-sandbox

PHP Sandbox (with Shortcodes)

A secure PHP sandbox plugin for WordPress that allows execution of PHP code through shortcodes with proper security measures, user capability checks, and nonce verification.

by Umang Prajapati · github.com/umang48/wp-php-sandbox · website

★ 0stars
0forks

Install

No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:

wp plugin install https://github.com/umang48/wp-php-sandbox/archive/refs/heads/main.zip

A secure PHP sandbox plugin for WordPress that allows safe execution of PHP code through shortcodes with comprehensive security measures.

Description

WP PHP Sandbox (with Shortcodes) is a powerful WordPress plugin that provides a secure environment for executing PHP code through shortcodes. Perfect for developers, educators, and content creators who need to demonstrate PHP code functionality within WordPress posts and pages.

Key Features

  • Secure Code Execution: Advanced security measures prevent dangerous functions and unauthorized access
  • Multiple Shortcodes: Support for [php_sandbox], [php_code], and [php_execute] shortcodes
  • User Permission Control: Configurable user capability requirements
  • Execution Limits: Configurable timeout and memory limits for code execution
  • Function Whitelisting: Control which PHP functions are allowed
  • Comprehensive Logging: Track all code executions for security auditing
  • Admin Interface: User-friendly admin panel for configuration and testing
  • Syntax Highlighting: Optional code highlighting for better readability
  • Multiple Themes: Light and dark theme options
  • Nonce Security: Built-in CSRF protection with WordPress nonces

Security Features

  • Blocks dangerous functions (file operations, system commands, network functions)
  • User capability verification
  • Nonce-based request verification
  • Execution timeout limits
  • Memory usage limits
  • Function whitelisting
  • Comprehensive execution logging
  • Input sanitization and validation

Usage Examples

Basic usage: [php_sandbox]echo "Hello World!";[/php_sandbox]

With code display: [php_sandbox show_code="true"] $name = "WordPress"; echo "Hello " . $name . "!"; [/php_sandbox]

With custom theme: [php_sandbox theme="dark" show_code="true"] $numbers = array(1, 2, 3, 4, 5); echo "Sum: " . array_sum($numbers); [/php_sandbox]

Perfect For

  • Developers: Testing code snippets and demonstrations
  • Educators: Teaching PHP programming concepts
  • Bloggers: Creating interactive coding tutorials
  • Documentation: Providing live code examples

Installation

  1. Upload the plugin files to the /wp-content/plugins/wp-php-sandbox/ directory
  2. Activate the plugin through the 'Plugins' screen in WordPress
  3. Go to Tools > PHP Sandbox to configure the plugin settings
  4. Set appropriate user permissions and security settings
  5. Start using shortcodes in your posts and pages

Frequently Asked Questions

Is this plugin secure?

Yes, the plugin includes comprehensive security measures:

  • Blocks dangerous PHP functions
  • Enforces user permission checks
  • Implements execution limits
  • Uses WordPress nonces for CSRF protection
  • Logs all executions for auditing

What PHP functions are allowed?

By default, only safe functions are allowed. You can customize the allowed functions list in the plugin settings. Dangerous functions like file operations, system commands, and network functions are blocked.

Can I customize the appearance?

Yes, the plugin supports multiple themes (default and dark) and includes CSS classes for custom styling.

Who can execute PHP code?

By default, users with 'edit_posts' capability can execute code. This is configurable in the plugin settings and can be restricted to higher privilege levels.

Are executions logged?

Yes, all code executions are logged with timestamps, user information, and results for security auditing purposes.

Screenshots

  1. Admin interface for code execution and testing
  2. Plugin settings page with security options
  3. Execution logs for security auditing
  4. Help page with usage examples
  5. Shortcode output with code highlighting
  6. Dark theme example

Changelog

1.0.0

  • Initial release
  • Secure PHP code execution through shortcodes
  • Admin interface for configuration
  • Comprehensive security measures
  • Execution logging
  • Multiple shortcode options
  • Theme support
  • User permission controls

Security Considerations

This plugin is designed with security in mind, but please note:

  • Only grant execution permissions to trusted users
  • Regularly review execution logs
  • Keep the allowed functions list minimal
  • Test thoroughly in a development environment
  • Consider additional server-level security measures

Support

For support, feature requests, or bug reports, please visit the plugin's repository or contact the developer.

License

This plugin is licensed under the GPLv2 or later license.