
Base64 Shortlinks Security & Risk Analysis
wordpress.org/plugins/base64-shortlinksThis plugin makes your shortlinks shorter!
Is Base64 Shortlinks Safe to Use in 2026?
Generally Safe
Score 100/100Base64 Shortlinks has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'base64-shortlinks' plugin v1.7 exhibits a generally positive security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface, and crucially, no entry points were found to be unprotected. The code also demonstrates good practices by exclusively using prepared statements for SQL queries and performing no file operations or external HTTP requests, which are common vectors for vulnerabilities.
However, there are notable concerns regarding output escaping. With only 25% of outputs being properly escaped, there's a significant risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is rendered directly without sufficient sanitization. While taint analysis found no critical or high severity issues, the lack of nonces and capability checks on any potential, albeit currently non-existent, entry points represents a potential weakness. The plugin's vulnerability history is clean, with no recorded CVEs, which is a strong positive indicator. Overall, the plugin has a solid foundation with minimal attack vectors and no known vulnerabilities, but the insufficient output escaping is a critical area that needs immediate attention.
Key Concerns
- Insufficient output escaping
- No nonce checks
- No capability checks
Base64 Shortlinks Security Vulnerabilities
Base64 Shortlinks Code Analysis
Output Escaping
Base64 Shortlinks Attack Surface
WordPress Hooks 6
Maintenance & Trust
Base64 Shortlinks Maintenance & Trust
Maintenance Signals
Community Trust
Base64 Shortlinks Alternatives
Linker – URL shortener & track outbound link clicks
linker
Track Outbound Link Clicks Easily: Shorten & track your site links by using your own domain name. e.g. "your-domain.com/go/link"
Link Shortner
link-shortener
Link Shortner allows you to easily create clean, branded short permalink links for your posts custom URL.
Shortlinks for Jetpack sharing buttons
jetpack-shortlinks-for-sharing-buttons
Use shortlinks instead of permalinks in Jetpack sharing buttons
PublishPress Shortlinks – Custom URLs for Posts and External Links – Share Previews for Draft Posts
tinypress
Create custom links for your posts. These links are brandable, trackable, and can have custom view permissions.
Get Shortlinks
wp-shortlinks
Get the classic "Get shortlink" from WordPress 3.7. Developed to make it easier for people at Mentor to get shorlinks and open sourcing it.
Base64 Shortlinks Developer Profile
2 plugins · 30 total installs
How We Detect Base64 Shortlinks
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/base64-shortlinks/base64-shortlinks.css/wp-content/plugins/base64-shortlinks/base64-shortlinks.jsbase64-shortlinks/base64-shortlinks.css?ver=base64-shortlinks/base64-shortlinks.js?ver=HTML / DOM Fingerprints
b64sl-shortlink<!-- Base64 Shortlinks Settings --><!-- End Base64 Shortlinks Settings -->data-b64sl-idb64sl_vars[base64_shortlink]