All In One Link Shortener Security & Risk Analysis

wordpress.org/plugins/all-in-one-link-shortener

Create shortlinks for WordPress posts/pages using Bitly, TinyURL, Rebrandly, or native WordPress permalinks.

0 active installs v1.0.3 PHP 7.4+ WP 6.1+ Updated Oct 6, 2025
linkspermalinkseoshortlinkurl-shortener
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is All In One Link Shortener Safe to Use in 2026?

Generally Safe

Score 100/100

All In One Link Shortener has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7mo ago
Risk Assessment

The static analysis of all-in-one-link-shortener v1.0.3 reveals a generally strong security posture. The plugin demonstrates excellent adherence to secure coding practices, with all SQL queries utilizing prepared statements and all output being properly escaped. Furthermore, the absence of dangerous functions, file operations, and recorded vulnerabilities in its history are significant strengths.

However, there are minor areas for consideration. The plugin makes six external HTTP requests, which, while not inherently a vulnerability, can be a vector for supply chain attacks or unintended data exposure if the external services are compromised. Additionally, the presence of two entry points (1 AJAX handler and 1 shortcode) with security checks indicates a well-defined and protected attack surface. The lack of critical or high-severity taint flows is positive, but the limited scope of taint analysis (0 flows analyzed) means it cannot definitively rule out all potential issues in this area.

Overall, all-in-one-link-shortener v1.0.3 appears to be a secure plugin due to its diligent implementation of core security practices and its clean vulnerability history. The primary, albeit minor, concern relates to its external HTTP requests. The limited scope of taint analysis prevents a complete assessment in that specific area.

Key Concerns

  • External HTTP requests detected
  • Limited scope of taint analysis
Vulnerabilities
None known

All In One Link Shortener Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

All In One Link Shortener Release Timeline

v1.0.3Current
v1.0.2
v1.0.1
v1.0
Code Analysis
Analyzed Apr 16, 2026

All In One Link Shortener Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
63 escaped
Nonce Checks
2
Capability Checks
2
File Operations
0
External Requests
6
Bundled Libraries
0

Output Escaping

100% escaped63 total outputs
Attack Surface

All In One Link Shortener Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 1

authwp_ajax_aiols_generate_shortlinkincludes/class-aiols-admin-columns.php:17

Shortcodes 1

[aiols_shortlink] all-in-one-link-shortener.php:82
WordPress Hooks 14
actioninitall-in-one-link-shortener.php:79
actionadmin_initall-in-one-link-shortener.php:80
actionsave_postall-in-one-link-shortener.php:81
filterpost_row_actionsall-in-one-link-shortener.php:83
actionadmin_post_aiols_regenerateall-in-one-link-shortener.php:84
filterget_sample_permalink_htmlall-in-one-link-shortener.php:86
actionadmin_enqueue_scriptsall-in-one-link-shortener.php:88
filtermanage_post_posts_columnsincludes/class-aiols-admin-columns.php:13
actionmanage_post_posts_custom_columnincludes/class-aiols-admin-columns.php:14
actionadmin_menuincludes/class-aiols-admin-settings.php:13
actionadmin_initincludes/class-aiols-admin-settings.php:14
filterbulk_actions-edit-postincludes/class-aiols-bulk-actions.php:13
filterhandle_bulk_actions-edit-postincludes/class-aiols-bulk-actions.php:14
actionadmin_noticesincludes/class-aiols-bulk-actions.php:15
Maintenance & Trust

All In One Link Shortener Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 6, 2025
PHP min version7.4
Downloads343

Community Trust

Rating100/100
Number of ratings2
Active installs0
Developer Profile

All In One Link Shortener Developer Profile

Shitalben Parmar

2 plugins · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect All In One Link Shortener

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/all-in-one-link-shortener/assets/js/admin-aiols-shortlink.js
Script Paths
/wp-content/plugins/all-in-one-link-shortener/assets/js/admin-aiols-shortlink.js
Version Parameters
all-in-one-link-shortener/assets/js/admin-aiols-shortlink.js?ver=1.0.0

HTML / DOM Fingerprints

CSS Classes
aiols-copy-shortlink
Data Attributes
data-shortlink
JS Globals
aiols_js
FAQ

Frequently Asked Questions about All In One Link Shortener