
Kael.me URL Shortener Security & Risk Analysis
wordpress.org/plugins/kaelme-url-shortenerkael.me URL shortener let you create your own short url, just like http://yoursite/-abc, instead of using other short url services
Is Kael.me URL Shortener Safe to Use in 2026?
Generally Safe
Score 85/100Kael.me URL Shortener has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'kaelme-url-shortener' plugin version 1.0.1 exhibits a concerning security posture despite a seemingly small attack surface and no reported vulnerabilities in its history. The static analysis reveals significant weaknesses in secure coding practices. Notably, 100% of SQL queries are not using prepared statements, posing a high risk of SQL injection vulnerabilities. Furthermore, 0% of output escaping is properly implemented, meaning any data rendered to the user could be vulnerable to cross-site scripting (XSS) attacks. The taint analysis indicates that all analyzed flows have unsanitized paths, which, in conjunction with the lack of output escaping and raw SQL queries, presents a substantial risk of code execution and data manipulation. While the plugin has no known CVEs and no specific vulnerability history, the internal code analysis highlights a high potential for exploitable flaws. The absence of capability checks, nonce checks, and authentication checks on potential entry points (even though reported as zero in this specific analysis) is a general concern for plugins handling any form of data, as these checks are fundamental to WordPress security. The plugin's security is significantly undermined by its poor implementation of core security practices.
Key Concerns
- All SQL queries use raw SQL, no prepared statements
- No output escaping is properly implemented
- All analyzed taint flows have unsanitized paths
- 0% capability checks implemented
- 0% nonce checks implemented
Kael.me URL Shortener Security Vulnerabilities
Kael.me URL Shortener Release Timeline
Kael.me URL Shortener Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Kael.me URL Shortener Attack Surface
WordPress Hooks 1
Maintenance & Trust
Kael.me URL Shortener Maintenance & Trust
Maintenance Signals
Community Trust
Kael.me URL Shortener Alternatives
Short URL Generator
shortcode-shorturl
This plugin automatically generates a Short URL for your article. You can choose your favorite provider and get multiple options.
Bitly URL Shortener
codehaveli-bitly-url-shortener
Bitly URL Shortener uses the functionality of Bitly API to generate Bitly short link without leaving your WordPress site.
URL Shortener
url-shortener
This plugin allows you to generate shortlinks for post/pages using URL Shorteners (e.g. Bit.ly, Su.pr, YOURLS, Goo.gl and many others).
GentleSource Short URL
gentlesource-short-url
Automatically shortens the blog post URL.
Plink URL Shortener
plink-url-shortener
Automatic wordpress link shortener, shortens posts, pages, categories, affiliate links, shorten external links or any URL via plink.ir
Kael.me URL Shortener Developer Profile
1 plugin · 10 total installs
How We Detect Kael.me URL Shortener
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/kaelme-url-shortener/css/style.css/wp-content/plugins/kaelme-url-shortener/js/km_shortener.js/wp-content/plugins/kaelme-url-shortener/js/km_shortener.jskaelme-url-shortener/css/style.css?ver=kaelme-url-shortener/js/km_shortener.js?ver=HTML / DOM Fingerprints
url shortener plugin admin start