
Custom Shortlink Structure Security & Risk Analysis
wordpress.org/plugins/custom-shortlink-structureChange the default WordPress shortlink structure dynamically just like you can change your permalinks.
Is Custom Shortlink Structure Safe to Use in 2026?
Generally Safe
Score 85/100Custom Shortlink Structure has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "custom-shortlink-structure" v1.0 exhibits a mixed security posture. On the positive side, it has no known vulnerabilities and demonstrates good practices regarding SQL queries, ensuring all are prepared statements. The absence of file operations, external HTTP requests, and bundled libraries further reduces potential attack vectors. However, significant concerns arise from the static analysis, particularly the output escaping. With only 33% of outputs properly escaped, there's a clear risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the site. The taint analysis, while not revealing critical or high severity issues, did find two flows with unsanitized paths, which could potentially lead to vulnerabilities if exploited in conjunction with other weaknesses. The complete lack of AJAX handlers, REST API routes, shortcodes, cron events, nonce checks, and capability checks, while seemingly reducing the attack surface to zero, also means there are no built-in security mechanisms for any potential future additions or unforeseen interactions, making it difficult to assess its resilience against evolving threats. The vulnerability history being entirely clean is a positive indicator, but it doesn't negate the immediate risks identified in the code itself. The overall security posture is therefore one of caution, with immediate risks from inadequate output escaping needing urgent attention.
Key Concerns
- Low output escaping percentage
- Flows with unsanitized paths detected
- No capability checks
- No nonce checks
Custom Shortlink Structure Security Vulnerabilities
Custom Shortlink Structure Code Analysis
Output Escaping
Data Flow Analysis
Custom Shortlink Structure Attack Surface
WordPress Hooks 7
Maintenance & Trust
Custom Shortlink Structure Maintenance & Trust
Maintenance Signals
Community Trust
Custom Shortlink Structure Alternatives
Custom Post Type Permalinks
custom-post-type-permalinks
Edit the permalink of custom post type.
Remove Category URL – Remove 'category' base from category permalinks
remove-category-url
Remove Category URL strips the /category/ base from your category URLs, turning something like /category/my-category/ into simply /my-category/.
Custom Permalink Editor
custom-permalink-editor
Set Custom Permalink Editor on a per-post, per-tag per-page, and per-category basis.
Bitly's WordPress Plugin
wp-bitly
Create short links to your content with Bitly’s WordPress Plugin.
Enhanced Custom Permalinks
enhanced-custom-permalinks
Set custom permalinks on a per-post, per-tag or per-category basis.
Custom Shortlink Structure Developer Profile
4 plugins · 10K total installs
How We Detect Custom Shortlink Structure
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-shortlink-structure/css/shortlink-structure.css/wp-content/plugins/custom-shortlink-structure/js/shortlink-structure.jscustom-shortlink-structure/css/shortlink-structure.css?ver=custom-shortlink-structure/js/shortlink-structure.js?ver=HTML / DOM Fingerprints
name="csls-settings[rule]"name="csls-settings[custom]"id="csls-settings-custom"name="csls-settings[rules][id="shortlinks-custom"<code>?p=%post_id%</code><code>s/%post_id%</code><code>-%post_id%</code><code>~%post_id%</code>