
Better YOURLS Security & Risk Analysis
wordpress.org/plugins/better-yourlsIntegrate your blog with YOURLS custom URL generator.
Is Better YOURLS Safe to Use in 2026?
Generally Safe
Score 85/100Better YOURLS has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "better-yourls" v2.3.0 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its attack surface, and crucially, there are no identified unprotected entry points. The code also demonstrates good practices with 100% of SQL queries using prepared statements and a single external HTTP request being present. The presence of nonce and capability checks, though minimal, is a positive sign. The taint analysis shows no identified critical or high-severity flows, which is excellent. However, a weakness lies in the output escaping, where only 57% of outputs are properly escaped, indicating a potential risk for Cross-Site Scripting (XSS) vulnerabilities in the unescaped portions. The plugin's vulnerability history is completely clean, with no known CVEs, which suggests a history of secure development or a lack of past targeted attacks. Overall, this plugin appears to be well-developed from a security perspective, with its primary area for improvement being the consistent escaping of all output data.
Key Concerns
- Output escaping is not consistently applied
Better YOURLS Security Vulnerabilities
Better YOURLS Code Analysis
Output Escaping
Data Flow Analysis
Better YOURLS Attack Surface
WordPress Hooks 13
Maintenance & Trust
Better YOURLS Maintenance & Trust
Maintenance Signals
Community Trust
Better YOURLS Alternatives
YOURLS Link Creator
yourls-link-creator
Creates a custom short URL when saving posts. Requires your own YOURLS install.
Easy Affiliate Links
easy-affiliate-links
Easily manage and cloak all your affiliate links.
Linker – URL shortener & track outbound link clicks
linker
Track Outbound Link Clicks Easily: Shorten & track your site links by using your own domain name. e.g. "your-domain.com/go/link"
Bitly's WordPress Plugin
wp-bitly
Create short links to your content with Bitly’s WordPress Plugin.
Bring Back the Get Shortlink Button
bring-back-the-get-shortlink-button
This plugin brings back the Get Shortlink button, which is hidden by default since WordPress 4.4.
Better YOURLS Developer Profile
1 plugin · 300 total installs
How We Detect Better YOURLS
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/better-yourls/css/better-yourls-admin.css/wp-content/plugins/better-yourls/js/better-yourls-admin.js/wp-content/plugins/better-yourls/js/better-yourls-admin.jsbetter-yourls/css/better-yourls-admin.css?ver=better-yourls/js/better-yourls-admin.js?ver=HTML / DOM Fingerprints
yourls-keyword-input<!-- YOURLS Keyword --><!-- Link: --><!-- Copy to Clipboard --><!-- Keyword: -->+1 moredata-yourls-copy-textdata-yourls-copy-confirmbetter_yourls_admin_params