Orbisius Simple Shortlink Security & Risk Analysis

wordpress.org/plugins/orbisius-simple-shortlink

Allows you to redirect to page, post or any other custom post type.

40 active installs v1.0.4 PHP + WP 3.0+ Updated Oct 17, 2017
orbisiusredirecshort-linkshortlinkwp
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Orbisius Simple Shortlink Safe to Use in 2026?

Generally Safe

Score 85/100

Orbisius Simple Shortlink has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The "orbisius-simple-shortlink" plugin v1.0.4 exhibits a generally positive security posture based on the provided static analysis. The absence of direct entry points like AJAX handlers, REST API routes, shortcodes, and cron events significantly reduces its attack surface. Furthermore, the code doesn't utilize dangerous functions, perform file operations, make external HTTP requests, or contain any known vulnerability history, all of which are strong indicators of good security practices. The use of prepared statements for all SQL queries is also a commendable practice.

However, a significant concern arises from the low percentage of properly escaped output (8%). With 49 total outputs, this means a substantial number of user-facing data may be vulnerable to Cross-Site Scripting (XSS) attacks. While taint analysis shows no unsanitized paths, the lack of output escaping is a tangible risk that could be exploited. The plugin also lacks any nonce or capability checks, which, while not directly exploitable given the limited attack surface, indicates a potential for future issues if new entry points are introduced without proper authorization and security validation mechanisms.

In conclusion, the plugin has a strong foundation due to its minimal attack surface and the absence of known vulnerabilities. However, the widespread lack of output escaping is a critical weakness that needs immediate attention. While the absence of taint flows is reassuring, it's not a substitute for robust output sanitization. The lack of nonce and capability checks is a minor concern in the current state but represents a potential future risk.

Key Concerns

  • Low output escaping percentage
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Orbisius Simple Shortlink Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Orbisius Simple Shortlink Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
45
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

8% escaped49 total outputs
Attack Surface

Orbisius Simple Shortlink Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_menuorbisius-simple-shortlink-admin.php:3
filterplugin_action_linksorbisius-simple-shortlink-admin.php:16
actioninitorbisius-simple-shortlink.php:13
actionwporbisius-simple-shortlink.php:45
Maintenance & Trust

Orbisius Simple Shortlink Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedOct 17, 2017
PHP min version
Downloads4K

Community Trust

Rating100/100
Number of ratings2
Active installs40
Developer Profile

Orbisius Simple Shortlink Developer Profile

Svetoslav Marinov

26 plugins · 12K total installs

71
trust score
Avg Security Score
88/100
Avg Patch Time
722 days
View full developer profile
Detection Fingerprints

How We Detect Orbisius Simple Shortlink

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
orb_club_short_link_container
Data Attributes
addthis:urladdthis:titleaddthis:description
Shortcode Output
example.com/goto/example.com/page/example.com/link/example.com/post/
FAQ

Frequently Asked Questions about Orbisius Simple Shortlink