Shorten2Ping Security & Risk Analysis

wordpress.org/plugins/shorten2ping

Sends status updates to Ping.fm everytime you publish a post, using your own domain, bit.ly, wp.me, su.pr, is.gd and others for shortened permalinks.

40 active installs v1.4.8 PHP + WP 2.7+ Updated Mar 17, 2012
bit-lyfacebookpingping-fmtwitter
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Shorten2Ping Safe to Use in 2026?

Generally Safe

Score 85/100

Shorten2Ping has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 14yr ago
Risk Assessment

The shorten2ping v1.4.8 plugin exhibits a generally strong security posture due to the absence of known vulnerabilities and a clean taint analysis. The fact that all SQL queries utilize prepared statements is a significant positive practice. However, the complete lack of output escaping across all identified outputs is a critical concern and represents a significant security weakness. While the attack surface appears minimal with no direct entry points exposed, the lack of proper output sanitization means that any data processed by the plugin, even if it doesn't directly come from user input through traditional entry points, could potentially be rendered unsafely, leading to cross-site scripting (XSS) vulnerabilities if the data is later displayed. The absence of nonce and capability checks also contributes to a less secure handling of potential interactions, though the limited attack surface mitigates this risk somewhat in this specific version. Overall, the plugin benefits from a clean vulnerability history but is severely hampered by its output escaping deficiencies.

Key Concerns

  • All outputs are unescaped
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Shorten2Ping Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Shorten2Ping Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
18
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
6
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

0% escaped18 total outputs
Attack Surface

Shorten2Ping Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionplugins_loadedshorten2ping.php:863
actionadmin_initshorten2ping.php:903
actionnew_to_publishshorten2ping.php:904
actiondraft_to_publishshorten2ping.php:905
actionpending_to_publishshorten2ping.php:906
actionfuture_to_publishshorten2ping.php:907
actionadmin_menushorten2ping.php:908
actionwp_headshorten2ping.php:910
actionwp_headshorten2ping.php:911
Maintenance & Trust

Shorten2Ping Maintenance & Trust

Maintenance Signals

WordPress version tested3.3.2
Last updatedMar 17, 2012
PHP min version
Downloads42K

Community Trust

Rating0/100
Number of ratings0
Active installs40
Developer Profile

Shorten2Ping Developer Profile

Samuel Aguilera

14 plugins · 98K total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Shorten2Ping

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/shorten2ping/css/shorten2ping.css/wp-content/plugins/shorten2ping/js/shorten2ping.js
Script Paths
/wp-content/plugins/shorten2ping/js/shorten2ping.js
Version Parameters
shorten2ping/css/shorten2ping.css?ver=shorten2ping/js/shorten2ping.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- Shorturl added by shorten2ping --><!-- Img for Facebook thumbnail added by Shorten2Ping -->
Data Attributes
rel="shorturl"property="og:image"
Shortcode Output
<a href="
FAQ

Frequently Asked Questions about Shorten2Ping