
Short.bg URL Shortener Security & Risk Analysis
wordpress.org/plugins/short-bg-url-shortenerShorten post URLs via Short.bg API directly from the WordPress editor.
Is Short.bg URL Shortener Safe to Use in 2026?
Generally Safe
Score 100/100Short.bg URL Shortener has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "short-bg-url-shortener" plugin v1.0.0 exhibits a generally strong security posture based on the provided static analysis. A significant positive is the complete absence of raw SQL queries, with all 100% utilizing prepared statements, mitigating SQL injection risks. Furthermore, the plugin correctly implements nonce and capability checks for its entry points, and there are no critical or high severity taint flows identified, indicating robust input sanitization and validation. The absence of any known historical vulnerabilities further suggests a commitment to security. However, a notable concern is the escaping of output, with only 68% of the 34 total outputs being properly escaped. This leaves 32% of outputs potentially vulnerable to cross-site scripting (XSS) attacks if user-supplied data is not meticulously handled elsewhere.
While the attack surface is small (2 AJAX handlers) and currently unprotected entry points are zero, the fact that 32% of outputs are unescaped is the primary weakness. If any of these unescaped outputs handle user-provided data without further sanitization, it could lead to stored or reflected XSS vulnerabilities. The plugin's single external HTTP request also warrants attention, though its exact function is not detailed, it could potentially be an avenue for vulnerabilities if not handled securely. Overall, the plugin is built on solid security foundations but has room for improvement in output sanitization to achieve a fully secure status.
Key Concerns
- Unescaped output (32% of 34 outputs)
Short.bg URL Shortener Security Vulnerabilities
Short.bg URL Shortener Code Analysis
Output Escaping
Short.bg URL Shortener Attack Surface
AJAX Handlers 2
WordPress Hooks 5
Maintenance & Trust
Short.bg URL Shortener Maintenance & Trust
Maintenance Signals
Community Trust
Short.bg URL Shortener Alternatives
URL Short tool by Shorterm – Simple, Fast & Private
shorterm
Lightweight WordPress URL Shortener. Create custom slugs, cloak affiliate links & track clicks without slowing down your site.
Tiny1z Short URLs
tiny1z-short-urls
Automatically generate and manage Tiny1z short URLs for posts, pages, and WooCommerce products. Modern, fast, and easy to use.
URL Shortify – Simple and Easy URL Shortener
url-shortify
URL Shortify helps you beautify, manage, share & cloak any links on or off your WordPress website. Create links using your domain name!
Link Shortner
link-shortener
Link Shortner allows you to easily create clean, branded short permalink links for your posts custom URL.
Bitly URL Shortener
codehaveli-bitly-url-shortener
Bitly URL Shortener uses the functionality of Bitly API to generate Bitly short link without leaving your WordPress site.
Short.bg URL Shortener Developer Profile
2 plugins · 0 total installs
How We Detect Short.bg URL Shortener
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/short-bg-url-shortener/css/shortbg-admin.css/wp-content/plugins/short-bg-url-shortener/js/shortbg-admin.jsshort-bg-url-shortener/css/shortbg-admin.css?ver=short-bg-url-shortener/js/shortbg-admin.js?ver=HTML / DOM Fingerprints
shortbg-widget<!-- Generated by Short.bg -->data-noncedata-api-keydata-action-shortendata-action-clearshortbgAdminshortbgAdminData/wp-json/shortbg/v1/shorten/wp-json/shortbg/v1/clear