
Shorten2List Security & Risk Analysis
wordpress.org/plugins/shorten2listSends status updates to selected maillists everytime you publish a post, using your own domain or others for shortened permalinks.
Is Shorten2List Safe to Use in 2026?
Generally Safe
Score 85/100Shorten2List has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "shorten2list" plugin v1.1 presents a mixed security posture. While the static analysis indicates a very small attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events exposed without authentication, several critical concerns emerge from the code signals. Notably, a significant portion of SQL queries are not using prepared statements, and 100% of output escaping is improperly handled. Furthermore, the plugin makes external HTTP requests and lacks any nonce or capability checks, which are fundamental security measures. The taint analysis revealed two flows with unsanitized paths, although these were not classified as critical or high severity, this still indicates a potential for data manipulation if these flows are triggered. The complete absence of any recorded vulnerabilities in its history is a positive indicator, suggesting past development might have been secure or that the plugin has not been a target. However, the current code analysis reveals significant weaknesses that could be exploited in the absence of known vulnerabilities.
Key Concerns
- 50% SQL queries not using prepared statements
- 0% output escaping properly handled
- 2 flows with unsanitized paths
- No nonce checks
- No capability checks
- Bundled outdated library (DataTables v1.6.1)
Shorten2List Security Vulnerabilities
Shorten2List Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Shorten2List Attack Surface
WordPress Hooks 7
Maintenance & Trust
Shorten2List Maintenance & Trust
Maintenance Signals
Community Trust
Shorten2List Alternatives
Shorten2Ping
shorten2ping
Sends status updates to Ping.fm everytime you publish a post, using your own domain, bit.ly, wp.me, su.pr, is.gd and others for shortened permalinks.
Shorten2PingNG
shorten2ping-ng
Sends status updates to Ping.fm or Twitter everytime you publish a post, using own domain or others for shortened permalinks.
WooCommerce
woocommerce
Everything you need to launch an online store in days and keep it growing for years. From your first sale to millions in revenue, Woo is with you.
SiteGuard WP Plugin
siteguard
SiteGurad WP Plugin is the plugin specialized for the protection against the attack to the management page and login.
Disable XML-RPC-API
disable-xml-rpc-api
A simple and lightweight plugin to disable XML-RPC API, X-Pingback and pingback-ping in WordPress 3.5+ for a faster and more secure website
Shorten2List Developer Profile
8 plugins · 150 total installs
How We Detect Shorten2List
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shorten2list/s2lstyle.css/wp-content/plugins/shorten2list/s2lscripts.js/wp-content/plugins/shorten2list/s2lscripts.jsshorten2list/s2lstyle.css?ver=shorten2list/s2lscripts.js?ver=HTML / DOM Fingerprints
<!-- Shorten2LIST Options -->id="shorten2list_options"name="mlname[]"name="mlfrom[]"name="mlto[]"name="mltrigger[]"